Skip to main content
QUICK REVIEW

[論文レビュー] Cloud computing security using encryption technique

Geethu Thomas, Prem Jose|arXiv (Cornell University)|Oct 31, 2013
Cloud Data Security Solutions参考文献 13被引用数 11
ひとこと要約

本稿では、対称暗号を用いた独立した鍵を用いて、静的および送信中データの保護に焦点を当てた包括的な暗号ベースのセキュリティフレームワークを提案する。データと暗号鍵を一緒に暗号化することにより、不正ユーザーがデータにアクセスしてもそれが解読不能であることを保証し、パブリッククラウド環境における機密性を著しく向上させる。

ABSTRACT

Cloud Computing has been envisioned as the next generation architecture of IT Enterprise. The Cloud computing concept offers dynamically scalable resources provisioned as a service over the Internet. Economic benefits are the main driver for the Cloud, since it promises the reduction of capital expenditure and operational expenditure. In order for this to become reality, however, there are still some challenges to be solved. Most important among these are security and trust issues,since the users data has to be released to the Cloud and thus leaves the protection sphere of the data owner.In contrast to traditional solutions, where the IT services are under proper physical,logical and personnel controls, Cloud Computing moves the application software and databases to the large data centers, where the management of the data and services may not be fully trustworthy. This unique attribute, however, poses many new security challenges which have not been well understood. Security is to save data from danger and vulnerability. There are so many dangers and vulnerabilities to be handled. Various security issues and some of their solution are explained and are concentrating mainly on public cloud security issues and their solutions. Data should always be encrypted when stored(using separate symmetric encryption keys)and transmitted. If this is implemented appropriately, even if another tenant can access the data, all that will appear is gibberish. So a method is proposed such that we are encrypting the whole data along with the cryptographic key.

研究の動機と目的

  • ユーザーの直接的管理外でデータが保存および処理されるパブリッククラウドコンピューティングにおける、深刻なセキュリティおよび信頼の課題に対処すること。
  • マルチテナント環境およびクラウドインfra構造に対する完全な制御の欠如に起因する脆弱性を克服すること。
  • 強力な暗号技術を用いて、静的および送信中データの両方を保護することで、エンドツーエンドのデータ機密性を確保すること。
  • 暗号化に使用される暗号鍵そのものも保護する実用的な手法を提案し、鍵の露呈を防止すること。
  • データの利用可能性を維持しつつ、不正アクセス時にデータ漏洩のリスクを最小限に抑えるソリューションを提供すること。

提案手法

  • データをクラウドにアップロードする前に、対称暗号を適用して機密性を保証すること。
  • 各データオブジェクトに対して別個で一意の対称鍵を用いることで、鍵の再利用を防ぎ、セキュリティの細分化を向上させること。
  • マスターキーまたは鍵管理システムを用いて、暗号鍵自体を暗号化することで、鍵素材の保護を実現すること。
  • 暗号化されたデータと暗号化された鍵を、クラウドに一緒に格納することで、正しい復号鍵を持つ承認済みユーザー以外が情報にアクセスできないようにすること。
  • データと鍵を一単位として暗号化する階層的暗号メカニズムを実装することで、鍵漏洩のリスクを低減すること。
  • パフォーマンスとセキュリティを確保するため、標準的な対称暗号アルゴリズム(文脈上、AESなど)を活用すること。

実験結果

リサーチクエスチョン

  • RQ1ユーザーの直接的管理外でデータが保存および処理されるパブリッククラウド環境において、どのようにしてデータ機密性を確保できるか?
  • RQ2攻撃者がクラウドストレージにアクセスした場合でも、暗号化されたデータへの不正アクセスをどのように防止できるか?
  • RQ3共有クラウドインfra構造上に暗号化データとともに格納される際、暗号鍵をどのように保護できるか?
  • RQ4データと鍵を一緒に暗号化することの、システムセキュリティおよびパフォーマンスに与える影響は何か?
  • RQ5クラウドコンピューティングの独自のセキュリティ課題に対応できる、スケーラブルで実用的な暗号モデルを設計できるか?

主な発見

  • 提案手法により、攻撃者がクラウドストレージにアクセスした場合でも、エンドツーエンド暗号化のおかげでデータは読み取れない。
  • データと暗号鍵を一緒に暗号化することで、鍵の露呈リスクが顕著に低減され、全体的なシステムセキュリティが向上する。
  • 各データオブジェクトごとに別個の対称鍵を用いることで、セキュリティの細分化が向上し、鍵の漏洩が発生した場合の被害範囲も限定される。
  • クラウドインfra構造の変更を要せず、既存のパブリッククラウド環境に容易に導入可能なため、データ機密性が維持される。
  • データ漏洩、内部者攻撃、マルチテナントリスクといった一般的な脅威に対して、効果的に対処できる。
  • パフォーマンスのオーバーヘッドを最小限に抑えつつ、クラウドコンピューティング環境における機密データ保護のための実用的でスケーラブルなソリューションを提供する。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。