To protect data on the servers of cloud service providers, file-sharing services rely on End-to-End Encryption (E2EE). However, existing solutions have weaknesses that allow attackers to bypass E2EE permanently after stealing a clients keys once. In this paper, a concept for an E2EE file-sharing service is proposed which does not have this vulnerability. It is based on Messaging Layer Security (MLS) groups for key distribution, an authentication system based on asymmetric cryptography, Attribute-Based Access Control (ABAC) based access rights and a tamper-proof versioned storage system for synchronising sensitive data. The applicability of the concept is demonstrated by a prototype implementation and an evaluation based on benchmarks and a security analysis. Overall, the concept can fulfil the requirements of a basic file sharing service while providing stronger security guarantees than existing solutions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Securing End-to-End Encrypted File Sharing Services with the Messaging Layer Security Protocol

  • Roland Helmich,
  • Lars Braubach,
  • Theresa Schulz,
  • Kai Jander

摘要

To protect data on the servers of cloud service providers, file-sharing services rely on End-to-End Encryption (E2EE). However, existing solutions have weaknesses that allow attackers to bypass E2EE permanently after stealing a clients keys once. In this paper, a concept for an E2EE file-sharing service is proposed which does not have this vulnerability. It is based on Messaging Layer Security (MLS) groups for key distribution, an authentication system based on asymmetric cryptography, Attribute-Based Access Control (ABAC) based access rights and a tamper-proof versioned storage system for synchronising sensitive data. The applicability of the concept is demonstrated by a prototype implementation and an evaluation based on benchmarks and a security analysis. Overall, the concept can fulfil the requirements of a basic file sharing service while providing stronger security guarantees than existing solutions.