About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
sesa 25(1):

Research Article

SeFS: A Secure and Efficient File Sharing Framework based on the Trusted Execution Environment

Download32 downloads
Cite
BibTeX Plain Text
  • @ARTICLE{10.4108/eetss.v9i1.2854,
        author={Yun He and Xiaoqi Jia and Shengzhi Zhang and Lou Chitkushev},
        title={SeFS: A Secure and Efficient File Sharing Framework based on the Trusted Execution Environment},
        journal={EAI Endorsed Transactions on Security and Safety},
        volume={9},
        number={1},
        publisher={EAI},
        journal_a={SESA},
        year={2025},
        month={7},
        keywords={Cloud storage, Trusted Execution Environment, Access Control},
        doi={10.4108/eetss.v9i1.2854}
    }
    
  • Yun He
    Xiaoqi Jia
    Shengzhi Zhang
    Lou Chitkushev
    Year: 2025
    SeFS: A Secure and Efficient File Sharing Framework based on the Trusted Execution Environment
    SESA
    EAI
    DOI: 10.4108/eetss.v9i1.2854
Yun He1,*, Xiaoqi Jia1, Shengzhi Zhang2, Lou Chitkushev2
  • 1: Chinese Academy of Sciences
  • 2: Boston University
*Contact email: 1224533208@qq.com

Abstract

As the cloud-based file sharing becomes increasingly popular, it is crucial to protect the outsourced data against unauthorized access. Existing cryptography-based approach suffers from expensive re-encryption upon permission revocation. Other solutions that utilize Trusted Execution Environment (TEE) to enforce access control either expose the plaintext keys to users or turn out incapable of handling concurrent requests. In this paper, we propose SeFS, a secure and practical file sharing framework that leverages cooperation of server-side and client-side enclaves to enforce access control, with the former responsible for registration, authentication and access control enforcement and the latter performing file decryption. Such design significantly reduces the computation workload of server-side enclave, thus capable of handling concurrent requests. Meanwhile, it also supports immediate permission revocation, since the file decryption keys inside the client-side enclaves are destroyed immediately after use. We implement a prototype of SeFS and the evaluation demonstrates it enforces access control securely with high throughput and low latency.

Keywords
Cloud storage, Trusted Execution Environment, Access Control
Received
2022-11-14
Accepted
2025-06-30
Published
2025-07-18
Publisher
EAI
http://dx.doi.org/10.4108/eetss.v9i1.2854

Copyright © 2025 Yun He et al., licensed to EAI. This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.

EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL