论文标题
企业内容应用程序的端到端加密解决方案
An End-to-End Encryption Solution for Enterprise Content Applications
论文作者
论文摘要
企业客户使用的内容主机服务(例如Dropbox,OneDrive和Google Drive)是在前提或云中部署的。由于用户可以在这些托管服务中存储对业务敏感的数据(内容),因此他们可能希望保护其数据免于向其他任何人(甚至IT管理员)披露。不幸的是,即使是目录(文件)也已在托管服务中加密,有时IT管理员仍然可以访问它们。如果IT管理员造成恶意(例如心怀不满的员工),或者他的帐户遭到黑客损害,则敏感数据可能会暴露于公众。 我们提出了一个端到端加密(E2EE)解决方案,以应对这一挑战。用户数据在客户端(移动设备)上进行加密,并保留在运输量和服务器上的静止状态。具体而言,我们设计了一种新方法,以允许大师秘密恢复和托管,同时保护它们免受恶意管理员的访问。此外,我们还提出了实现隐私和颗粒状访问控制的内容(文件)加密方案。它可以与当今业务用户使用的主要内容主机服务无缝集成。
The content host services (like Dropbox, OneDrive, and Google Drive) used by enterprise customers are deployed either on premise or in cloud. Because users may store business-sensitive data (contents) in these hosting services, they may want to protect their data from disclosure to anyone else, even IT administrators. Unfortunately, even contents (files) are encrypted in the hosting services, they sometimes are still accessible to IT administrators today. The sensitive data could be exposed to public if the IT administrator turns malicious (like disgruntled employee) or his account is compromised by hackers. We propose an end-to-end encryption (E2EE) solution to address this challenge. The user data is encrypted at client side (mobile device) and remains encrypted in transit and at rest on server. Specifically, we design a new method to allow master secret recover and escrow, while protecting them from being accessed by malicious administrators. In addition, we present a content (file) encryption scheme that achieves privacy, and granular access control. And it can be seamlessly integrated with major content host services used by business users today.