Title :
Cryptonite: A Secure and Performant Data Repository on Public Clouds
Author :
Kumbhare, Alok ; Simmhan, Yogesh ; Prasanna, Viktor
Author_Institution :
Comput. Sci. Dept., Univ. of Southern California, Los Angeles, CA, USA
Abstract :
Cloud storage has become immensely popular for maintaining synchronized copies of files and for sharing documents with collaborators. However, there is heightened concern about the security and privacy of Cloud-hosted data due to the shared infrastructure model and an implicit trust in the service providers. Emerging needs of secure data storage and sharing for domains like Smart Power Grids, which deal with sensitive consumer data, require the persistence and availability of Cloud storage but with client-controlled security and encryption, low key management overhead, and minimal performance costs. Cryptonite is a secure Cloud storage repository that addresses these requirements using a Strongbox model for shared key management. We describe the Cryptonite service and desktop client, discuss performance optimizations, and provide an empirical analysis of the improvements. Our experiments shows that Cryptonite clients achieve a 40% improvement in file upload bandwidth over plaintext storage using the Azure Storage Client API despite the added security benefits, while our file download performance is 5 times faster than the baseline for files greater than 100MB.
Keywords :
application program interfaces; cloud computing; public key cryptography; storage management; Azure storage client API; Cryptonite; Strongbox model; client-controlled security; cloud-hosted data; data sharing; encryption; low key management overhead; public clouds; secure cloud storage repository; secure data storage; shared key management; Cloud computing; Encryption; Libraries; Optimization; Public key; Cloud data storage; Data security; Secure data sharing;
Conference_Titel :
Cloud Computing (CLOUD), 2012 IEEE 5th International Conference on
Conference_Location :
Honolulu, HI
Print_ISBN :
978-1-4673-2892-0
DOI :
10.1109/CLOUD.2012.109