Towards Shared Ownership in the Cloud

Authors: Hubert Ritzdorf, Claudio Soriente, Ghassan Karame, Srdjan Marinovic, Damian Gruber, and Srdjan Čapkun
IEEE Transactions on Information Forensics and Security

Abstract

Cloud storage platforms promise a convenient way for users to share files and engage in collaborations, yet they require all files to have a single owner who unilaterally makes access control decisions. Existing clouds are, thus, agnostic to the notion of shared ownership. This can be a significant limitation in much collaboration because, for example, one owner can delete files and revoke access without consulting the other collaborators. In this paper, we first formally define a notion of shared ownership within a file access control model. We then propose two possible instantiations of our proposed shared ownership model. Our first solution, called Commune, relies on secure file dispersal and collusion-resistant secret sharing to ensure that all access grants in the cloud require the support of an agreed threshold of owners. As such, Commune can be used in existing clouds without modifications to the platforms. Our second solution, dubbed Comrade, leverages the blockchain technology in order to reach consensus on access control decision. Unlike Commune, Comrade requires that the cloud is able to translate access control decisions that reach consensus in the blockchain into storage access control rules, thus requiring minor modifications to existing clouds. We analyze the security of our proposals and compare/evaluate their performance through implementations using Amazon S3.

People

Dr. Hubert Ritzdorf
Doctoral Student (2012 – 2017)
CTO, ChainSecurity
Dr. Claudio Soriente
Doctoral Student (2012 – 2015)
Researcher, NEC Laboratories
Dr. Ghassan Karame
Doctoral Student (2007 – 2011)
Professor, Ruhr University Bochum 

BibTex

@article{ritzdorf2018towards,
  author    = {Ritzdorf, Hubert and Soriente, Claudio and Karame, Ghassan O. and Marinovic, Srdjan and Gruber, Damian and Capkun, Srdjan},
  title     = {{Towards Shared Ownership in the Cloud}},
  booktitle = {IEEE Transactions on Information Forensics and Security},
  year      = 2018,
  month     = may,
  publisher = {IEEE},
  doi       = {10.1109/TIFS.2018.2837648},
  url       = {https://doi.org/10.1109/TIFS.2018.2837648}
}

Research Collection: 20.500.11850/268466