A Secure and Lightweight Client-Side Deduplication Approach for Resisting Side Channel Attacks

Yuchen Chen, Chunfu Jia, Guanxiong Ha, Xuan Shan, Hang Chen · 2024

Client-side deduplication system is widely used in cloud storage systems to reduce storage and communication overhead by eliminating the storing and uploading of duplicate data. However, it is vulnerable to side channel attacks, where an adversary can infer the existence status of uploaded data based on deterministic relations in duplication check responses. To address this issue, Random Response (RARE) was proposed, which sends duplication check requests for two chunks simultaneously. Nevertheless, RARE has limitations in terms of communication efficiency and security. In this paper, we propose Random Zero-one Coding Response (RZCR) to overcome these limitations. RZCR achieves lightweight coding of multiple chunks using a novel linear mapping algorithm, allowing for a balance between security and performance through the adjustment of system parameters. Furthermore, we, for the first time, formally define a security game to model these side channel attacks in client-side deduplication systems and introduce a stronger threat model compared to RARE. Security analysis demonstrates that RZCR effectively mitigates the risk of side channel attacks. We also implement a prototype of RZCR and evaluate its performance using large-scale real-world datasets (i.e., Enron Email and Fslhomes) as well as synthetic datasets. The results show that RZCR significantly reduces communication overhead compared to representative schemes.

Read the paper · More papers on PaperTik