Client-Controlled Cloud Encryption

Florian Kerschbaum · 2014

Customers of cloud service demand control over their data. Next to threats to intellectual property, legal requirements and risks, such as data protection compliance or the possibility of a subpoena of the cloud service provider, also pose restrictions. A commonly proposed and implemented solution is to encrypt the data on the client and retain the key at the client. In this tutorial we will review: - the available encryption methods, such deterministic, order-preserving, homomorphic, searchable (functional) encryption and secure multi-party computation, - possible attacks on currently deployed systems like dictionary and frequency attacks, - architectures integrating these solutions into SaaS and PaaS (DBaaS) applications.

Read the paper · More papers on PaperTik