Data Security and Privacy in the Cloud
Sara Foresti
Dipartimento di Informatica Università degli Studi di Milano
sara.foresti@unimi.it Secure Cloud Services and Storage Workshop 2017
September 10, 2017 – Oslo, Norway
c SPDP Lab 1/32
Data Security and Privacy in the Cloud Sara Foresti Dipartimento di - - PowerPoint PPT Presentation
Data Security and Privacy in the Cloud Sara Foresti Dipartimento di Informatica Universit degli Studi di Milano sara.foresti@unimi.it Secure Cloud Services and Storage Workshop 2017 September 10, 2017 Oslo, Norway SPDP Lab c 1/32
c SPDP Lab 1/32
c SPDP Lab 2/32
data owner cloud data owner cloud
c SPDP Lab 3/32
functionality data owner cloud data owner cloud
c SPDP Lab 3/32
functionality but no protection (key is with the CSP) data owner cloud data owner cloud
c SPDP Lab 3/32
functionality but no protection (key is with the CSP) protection data owner cloud data owner cloud
c SPDP Lab 3/32
functionality but no protection (key is with the CSP) protection but limited functionality (you cannot access data as you like) data owner cloud data owner cloud
c SPDP Lab 3/32
data owner cloud
H2020 project “Enforceable Security in the Cloud to Uphold Data Ownership” (ESCUDO-CLOUD). c SPDP Lab 4/32
H2020 project “Enforceable Security in the Cloud to Uphold Data Ownership” (ESCUDO-CLOUD). c SPDP Lab 4/32
P . Samarati, S. De Capitani di Vimercati, “Cloud Security: Issues and Concerns,” in Encyclopedia on Cloud Computing,
c SPDP Lab 5/32
P . Samarati, S. De Capitani di Vimercati, “Cloud Security: Issues and Concerns,” in Encyclopedia on Cloud Computing,
c SPDP Lab 5/32
. Samarati, “Encryption Policies for Regulating Access to Outsourced Data,” in ACM Transactions on Database Systems (TODS), vol. 35, n. 2, April 2010, pp. 12:1-12:46.
c SPDP Lab 7/32
c SPDP Lab 8/32
c SPDP Lab 9/32
c SPDP Lab 10/32
A kA k1 r1 B kB k2 r2 C kC k3 r3 D kD k4 r4 E kE k5 r5 c SPDP Lab 11/32
A v1[A] v7[ABC] r1 B v2[B] v10[BC] C v3[C] v9[ABCD] r2 D v4[D] v8[BCD] r3 E v5[E] v6[DE] r4,r5 c SPDP Lab 12/32
c SPDP Lab 13/32
c SPDP Lab 14/32
c SPDP Lab 15/32
c SPDP Lab 16/32
c SPDP Lab 16/32
c SPDP Lab 17/32
c SPDP Lab 17/32
c SPDP Lab 17/32
. Samarati, “Mix&Slice: Efficient Access Revocation in the Cloud,” in Proc. of the 23rd ACM Conference on Computer and Communications Security (CCS 2016), Vienna, Austria, October 2016. c SPDP Lab 18/32
c SPDP Lab 19/32
c SPDP Lab 20/32
c SPDP Lab 20/32
c SPDP Lab 20/32
c SPDP Lab 21/32
E E E E E E E E
[0] [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15]
1 1 1 1
[8] [9] [10] [11]
1 1 1 1
[4] [5] [6] [7]
1 1 1 1
[0] [1] [2] [3]
1 1 1 1
[12] [13] [14] [15]
2 2 2 2
[0] [1] [2] [3]
2 2 2 2
[4] [5] [6] [7]
2 2 2 2
[8] [9] [10] [11] [12] [13] [14] [15]
2 2 2 2
c SPDP Lab 22/32
c SPDP Lab 23/32
c SPDP Lab 24/32
fragment macroblock F2 F5 F7
0 F8
F1 F3 F6 F9 F11
0 F12
F14
0 F15
F0 F13 F4 F10 c SPDP Lab 25/32
k e y fragment macroblock k 0 k 1 F10
1
F2 F5 F7
0 F8
F1 F3 F6 F9 F11
0 F12
F14
0 F15
F0 F13 F4 c SPDP Lab 25/32
key fragment macroblock k 0 k 1 k 2 F4
2
F10
1
F2 F5 F7
0 F8
F1 F3 F6 F9 F11
0 F12
F14
0 F15
F0 F13 c SPDP Lab 25/32
key fragment macroblock k 0 k 1 k 2 k 3 F4
2
F10
3
F2 F5 F7
0 F8
F1 F3 F6 F9 F11
0 F12
F14
0 F15
F0 F13 c SPDP Lab 25/32
c SPDP Lab 26/32
. Samarati, “Access Control Management for Secure Cloud Storage,” in Proc. of SecureComm 2016, Guangzhou, China, October 10-12, 2016.
c SPDP Lab 28/32
c SPDP Lab 29/32
c SPDP Lab 30/32
c SPDP Lab 30/32
c SPDP Lab 31/32
c SPDP Lab 31/32
c SPDP Lab 32/32