Security and Privacy in Communication Networks. 6th Iternational ICST Conference, SecureComm 2010, Singapore, September 7-9, 2010. Proceedings

Research Article

FADE: Secure Overlay Cloud Storage with File Assured Deletion

Download
531 downloads
  • @INPROCEEDINGS{10.1007/978-3-642-16161-2_22,
        author={Yang Tang and Patrick Lee and John Lui and Radia Perlman},
        title={FADE: Secure Overlay Cloud Storage with File Assured Deletion},
        proceedings={Security and Privacy in Communication Networks. 6th Iternational ICST Conference, SecureComm 2010, Singapore, September 7-9, 2010. Proceedings},
        proceedings_a={SECURECOMM},
        year={2012},
        month={5},
        keywords={Policy-based file assured deletion cloud storage prototype implementation},
        doi={10.1007/978-3-642-16161-2_22}
    }
    
  • Yang Tang
    Patrick Lee
    John Lui
    Radia Perlman
    Year: 2012
    FADE: Secure Overlay Cloud Storage with File Assured Deletion
    SECURECOMM
    Springer
    DOI: 10.1007/978-3-642-16161-2_22
Yang Tang1,*, Patrick Lee1,*, John Lui1,*, Radia Perlman2,*
  • 1: The Chinese University of Hong Kong
  • 2: Intel Labs
*Contact email: tangyang@cse.cuhk.edu.hk, pclee@cse.cuhk.edu.hk, cslui@cse.cuhk.edu.hk, radiaperlman@gmail.com

Abstract

While we can now outsource data backup to third-party cloud storage services so as to reduce data management costs, security concerns arise in terms of ensuring the privacy and integrity of outsourced data. We design , a practical, implementable, and readily deployable cloud storage system that focuses on protecting deleted data with policy-based ile ssured letion. FADE is built upon standard cryptographic techniques, such that it encrypts outsourced data files to guarantee their privacy and integrity, and most importantly, assuredly deletes files to make them unrecoverable to anyone (including those who manage the cloud storage) upon revocations of file access policies. In particular, the design of FADE is geared toward the objective that it acts as an overlay system that works seamlessly atop today’s cloud storage services. To demonstrate this objective, we implement a working prototype of FADE atop Amazon S3, one of today’s cloud storage services, and empirically show that FADE provides policy-based file assured deletion with a minimal trade-off of performance overhead. Our work provides insights of how to incorporate value-added security features into current data outsourcing applications.