In this paper, we introduce PASSAT, a practical system to boost the security assurance delivered by the current cloud architecture without requiring any changes or cooperation from the cloud service providers. PASSAT is an application transparent to the cloud servers that allows users to securely and efficiently store and access their files stored on public cloud storage based on a single master password. Using a fast and light-weight XOR secret sharing scheme, PASSAT secret-shares users' files and distributes them among n publicly available cloud platforms. To access the files, PASSAT communicates with any k out of n cloud platforms to receive the shares and runs a secret-sharing reconstruction algorithm to recover the files. An attacker (insider or outsider) who compromises or colludes with less than k platforms cannot learn the user's files or modify the files stealthily. To authenticate the user to multiple cloud platforms, PASSAT crucially stores the authentication credentials, specific to each platform on a password manager, protected under the user's master password. Upon requesting access to files, the user enters the password to unlock the vault and fetches the authentication tokens using which PASSAT can interact with cloud storage. Our instantiation of PASSAT based on (2, 3)-XOR secret sharing of Kurihara et al., implemented with three popular storage providers, namely, Google Drive, Box, and Dropbox, confirms that our approach can efficiently enhance the confidentiality, integrity, and availability of the stored files with no changes on the servers.
翻译:在本文中,我们引入了PASSAT,这是加强当前云层架构提供的安全保障的实用系统,不需要云层服务供应商进行任何改变或合作。PASSAT是云层服务器的一种透明应用,使用户能够在单一主密码的基础上安全、高效地储存和访问储存在公共云层中的文件。使用快速和轻量XOR秘密共享计划,PASSAT秘密分享用户文件,并在公开提供的云平台中分发这些文件。为了访问文件,PASSAT与任何来自n云平台的 k 进行通信,以接收股份,并运行一个秘密共享重建算法,以恢复文件。攻击者(内行或外部人员)以低于k的平台进行妥协或串通,无法安全、高效地存储和存取在公共云中存储的文件。要将用户认证证书认证到多个云层平台,PASSAT秘密共享的3号存储者,通过用户主口号密码保护每个平台的认证证书。在访问文件时,用户将密码输入密码以打开库库并获取认证文件的代码,在3号的存储服务器上(2PASSAT)的存储服务器上进行互动。