Scalable Client-side Encrypted Deduplication beyond Secret Sharing of the Master Key

Yuchen Chen, Guanxiong Ha, Xuan Shan, Chunfu Jia, Qiaowen Jia · 2024

Individuals and companies increasingly adopt encrypted deduplication systems for their enhanced security and efficiency benefits. Server-aided encrypted deduplication systems are the state-of-the-art scheme to resist brute-force attacks. However, it is overly reliant on a single centralized key server and vulnerable to a single point of failure. To this end, existing schemes have implemented distributed key servers based on secret sharing of the master key to resist a single point of failure. Nevertheless, this design has some inherent limitations in balancing security and scalability. Secret sharing of the master key effectively mitigates single points of failure, while negatively impacting system scalability. To address the above limitations, we propose a scalable client-side encrypted deduplication with distributed key servers based on secret sharing of the data key. To resist brute-force attacks, we also design a double-layer matching mechanism to achieve secure and effective duplicate check and key delivery. Additionally, drawing inspiration from random oracle models, we put forward a pseudo-random response strategy for key servers to safeguard key privacy effectively. Rigorous theoretical analysis and extensive experiments demonstrate that our scheme achieves both security and scalability, which is well-suited for deployment in large-scale systems and offers robust protection against a single point of failure.

Read the paper · More papers on PaperTik