CryFS: Design and Implementation of a Provably Secure Encrypted Cloud Filesystem

Sebastian Messmer · 2015

Cloud storage as offered by Dropbox and others is increasingly important for companies and individuals alike. However, the most cited limiting factors are confidentiality and integrity risks. To the best of our knowledge, there are no solutions that are secure and also easy enough to be used for cloud storage, and no solution for which there have been security proofs published. We introduce CryFS, a transparent and easy to use cryptographic filesystem, designed to be used with third party cloud storage solutions. Filesystem data is split into same-size blocks to be encrypted individually. This ensures confidentiality of file contents, file metadata and the directory structure. Integrity is achieved by keeping additional data like block version counters. We prove confidentiality and integrity using game based security notions. Different design alternatives are discussed and we develop balanced left-max-data trees, a tree data structure used by CryFS, which we prove to have minimal space overhead and to allow fast filesystem operations. We also provide a CryFS implementation and show that the filesystem is fast, allowing it to be used in practice.

Read the paper · More papers on PaperTik