SECURITY OF CLOUD STORAGE AND CLOUD COMPUTING



Similar documents
Performance Analysis of Client Side Encryption Tools

Analyzing the Security Schemes of Various Cloud Storage Services

Manual for Android 1.5

ECE 646, CRYPTOGRAPHY PROJECT SPECIFICATION GEORGE MASON UNIVERSITY FALL, 2013

Last modified: November 22, 2013 This manual was updated for the TeamDrive Android client version

A Secure and Efficient Client-Side Encryption Scheme in Cloud Computing

Cloud Computing for Education Workshop

Secure Cross Border File Protection & Sharing for Enterprise Product Brief CRYPTOMILL INC

HiDrive Intelligent online storage for private and business users.

Cloud Sync White Paper. Based on DSM 6.0

Business and enterprise cloud sync, backup and sharing solutions

SOOKASA WHITEPAPER SECURITY SOOKASA.COM

1. Scope of Service. 1.1 About Boxcryptor Classic

An Intelligent Approach for Data Fortification in Cloud Computing

The Security Behind Sticky Password

FileDrawer An Enterprise File Sharing and Synchronization (EFSS) solution.

Cloud Computing. Chapter 6 Data Storage in the Cloud

Storing and securing your data

Comparing Box and Egnyte. White Paper

Ahsay Online Backup. Whitepaper Data Security

ncrypted Cloud emerges from stealth mode with free data encryption offering

Data Superhero Online Backup Whitepaper Data Security

Cloud storage buyer s guide

IAIK. Motivation 2. Advanced Computer Networks 2015/2016. Johannes Feichtner IAIK

Access All Your Files on All Your Devices

IDENTIFYING THE OPTIMAL MULTI- USER DOCUMENT SHARING PLATFORM

Online Backup Service Frequently Asked Questions. 13 September 2010 Version 1.0

CAS CLOUD WEB USER GUIDE. UAB College of Arts and Science Cloud Storage Service

Storage Made Easy. Cloud File Server Overview

Thinking outside the (Drop)box: PKWARE targets enterprise file-share encryption

IONU PRO Product Overview

Anchor End-User Guide

Secure Data Exchange Solution

Yale Software Library. PGP 9.6 for Windows

Tresorit s DRM. A New Level of Security for Document Collaboration and Sharing

Sophos Mobile Control

The Genealogy Cloud: Which Online Storage Program is Right For You Page , copyright High-Definition Genealogy. All rights reserved.

Protecting Your Data On The Network, Cloud And Virtual Servers

COLLEAGUES. CLIENTS. CONNECTED. CLOUD.

SECURE YOUR DATA EXCHANGE WITH SAFE-T BOX

Providing an Enterprise File Share and Sync Solution for

Cloud Computing TODAY S TOPICS WHAT IS CLOUD COMPUTING? ICAC Webinar Cloud Computing September 4, What Cloud Computing is and How it Works

INFORMATION SECURITY GUIDELINE How to Encrypt Files Using Common Applications Revision 1.1

Storgrid EFS Access all of your business information securely from any device

Made Easy Windows Sync App Tutorial

SureDrop Secure collaboration. Without compromise.

YOUR SECURE ONLINE VAULT. DSWISS AG BADENERSTRASSE 281 CH-8003 ZURICH

Online File Folder. Getting Started Guide. Become an Expert at Managing Your Files Online. wind. Online File Folder // Getting Started Guide

Document OwnCloud Collaboration Server (DOCS) User Manual. How to Access Document Storage

CloudFTP: A free Storage Cloud

Cloudifile Getting Started

OBM / FREQUENTLY ASKED QUESTIONS (FAQs) Can you explain the concept briefly on how the software actually works? What is the recommended bandwidth?

Hosted File Backup for business. Keep your data safe with our cloud backup service

Utilizing Dropbox to Share Files

SecureVault Online Backup Service FAQ

Top Five Ways Any Business Can Benefit from Box

Vs Encryption Suites

Neat Cloud Service + Mobile App

The most comprehensive review and comparison of cloud storage services

SECURE BACKUP SYSTEM DESKTOP AND MOBILE-PHONE SECURE BACKUP SYSTEM HOSTED ON A STORAGE CLOUD

Securing Data at Rest ViSolve IT Security Team

In the Cloud. Scoville Memorial Library February, 2013

12 Key File Sync and Share Advantages of Transporter Over Box for Enterprise

Storing & Synchronizing Data In The Cloud

The Hybrid Cloud Advantage White Paper

CLOUD COMPUTING SECURITY ARCHITECTURE - IMPLEMENTING DES ALGORITHM IN CLOUD FOR DATA SECURITY

Storage, backup, transfer, encryption of data

2013 USER GROUP CONFERENCE

Problem. Solution. Quatrix is professional, secure and easy to use file sharing.

Privacy Patterns in Public Clouds

Personal Cloud. Support Guide for Mac Computers. Storing and sharing your content 2

Cloud Backup and Recovery for Endpoint Devices

PLATFORM ENCRYPTlON ARCHlTECTURE. How to protect sensitive data without locking up business functionality.

Transcription:

SECURITY OF CLOUD STORAGE AND CLOUD COMPUTING ECE 646 Final Presentation George Mason University GIRI PRANEETH KOMMALAPATI VENKAT RAMAN SRIPERUMBUDUR

Introduction Save and access the files online. Data stored in the cloud can be accessed from anywhere. There are many security threats faced by the User and the Cloud Service Provider. This cloud storage can be trusted when there is enough security from the server side. There are many security issues with the cloud computing. These security concerns are faced by both the providers and the consumers. In order to protect the data, the providers/organizations must ensure that the infrastructure is secure and the data of the consumers must be protected. The consumers must also be careful in selecting their passwords.

MOTIVATION There is a huge amount of data that is stored in the cloud. Over the years many popular cloud services like Dropbox, Amazon cloud service, icloud, etc. have been attacked by the hackers. Hackers attack the cloud and steal the information of many users. Although there are many attacks on the cloud, it is very important to store the sensitive data due to its huge advantages. Reducing or eliminating the problem of loosing sensitive data through reliable security at the client side. Fundamental services like confidentiality, availability, integrity and reliability are required for the consumers which are rendered by the CSP.

Hypothesis Main focus is on the analytical assessment of deployment of cryptools to safeguard the data. Some services a CSP must render are- Confidentiality: The data stored by the consumer must not be accessed by any other person including the service provider. Availability: The data must be accessible from anywhere from any computer/mobile phones, etc. Integrity: The data must not be modified by anyone other than the consumer by maintaining data integrity. Reliability: Data backup is a reliable task.

CRYPTOOLS The tools which we are using out of many for encryption are: SharedSafe Launcher for Windows Cloudfogger for Mac BoxCryptor for Windows Viivo SecretSync for Android AES Crypt for Windows Disk Cryptor for Windows

BASIC BLOCK DIAGRAM CLIENT Encryption& Decryption Tools Cloud Storage Key

SHAREDSAFE LAUNCHER simple way to share files on our FTP, e-mail, Dropbox with friends & co-workers. encrypts files with the well known AES-256 (Advanced Encryption Standard) and is an Open Source with client side encryption. protects files and file names before uploading. automatically shares files in the background and is available to operate offline. Encryption key is sent to receiver safely.

Sharedsafe installed and run Step-1

Step-2 Password created and safekey generated. Folder syncs automatically Client-side encryption

Fast and easy Encryption BOXCRYPTOR available for all the cloud storage providers like Dropbox, Sky drive, Google Drive, etc. supports all the clouds that use the WebDAV standard such as Cubby, Strato HiDrive and Owncloud. PGP can be used for sharing the files. It creates a Virtual Drive on our computer that allows us to encrypt our files locally before uploading them to the cloud. Boxcryptor uses the AES-256 and RSA-4096 encryption algorithms.

BOX CRYPTOR ENCRYPTION (CLIENT SIDE) RSA PRIVATE KEY KEY ENCRYPTION ENCRYPTED A PRIVATE KEY PASS KEY

BOX CRYPTOR ENCRYPTION (SERVER SIDE) CLOUD FILE AES-256 KEY ENCRYPTION ENCRYPTED FILE --------------------- A ENCRYPTED KEY ENCRYPTION With RSA public key

BOX CRYPTOR DECRYPTION PASSWORD RSA KEY DECRYPTION CLOUD PRIVATE KEY AES 256 A DECRYPTION ENCRYPTED FILE --------------------- ENCRYPTED KEY AKEY DECRYPTION FILE

DROP BOX BOXCRYPTOR

DROP BOX BOXCRYPTOR

DROP BOX BOXCRYPTOR

VIIVO VIIVO is a client side encryption tool used in android operating system. uses RSA 2048 and AES 256 algorithms to encrypt the data by creating an RSA key pair. The private key is secured with the password using PBKDF2 (Password-Based Key Derivation Function 2). The files are encrypted using AES-256 before they are uploaded in to the cloud. Most widely used by accountants, attorneys and Govt. & Health Care in the country.

VIIVO ENCRYPTION RSA PRIVATE KEY FILE PASSWORD (PBKDF2) ENCRYPTED KEY (USING AES-256) ENCRYPTED FILE CLOUD

AES CRYPT AES encrypts files using AES encryption. Files encrypted on one platform can be decrypted in other platforms. After encrypting the files locally we have to upload them to the cloud.

DISKCRYPTOR It offers encryption for all disk partitions. It uses AES-256, Twofish, Serpent and also their combinations. By cascading the algorithms, even if one algorithms is broken the data will be safe.

CLOUDFOGGER Cloudfogger for MAC allows manual encryption and decryption of files. Uses AES-256 and RSA-4096 algorithm for the encryption of files. Private key is encrypted using the RSA-4096 algorithm. Files are encrypted using AES-256 algorithm.

Observations BoxCryptor secures the file that are uploaded into dropbox by encrypting them with a safe key. SharedSafe is used for sharing the files and file names securely using safe key. SharedSafe when a file is uploaded, it s then encrypted and sent to a folder called My Safes. All the cryptools uses RSA-4096 and AES-256 algorithms for encryption of keys and files respectively. Cloud Fogger also uses same encryption algorithms at the client side. AES Crypt can be used to encrypt the files locally. Security mechanisms of all the tools are identical. Data can be shared using all the tools except AES Crypt and Disk Cryptor.

TOOL ENCRYPTION ALGORITHM USED SHARING PLATFORM Boxcryptor Client Side RSA 4096 AES 256 YES Windows, MAC, ios, Android Viivo Client Side RSA 4096 AES 256 Sharedsafe Client Side RSA 4096 AES 256 YES YES Windows, MAC, ios, Android Windows, MAC Cloudfogger Client Side RSA 4096 AES 256 AES Crypt DiskCryptor Single file encryption Tool Local drive encryption Tool Yes Windows, MAC, ios, Android AES NO Windows, MAC, Linux AES-256, Twofish, NO Windows

CONCLUSIONS Client side encryption is important before uploading data to the cloud. Through the analytical assessment of the cryptools, we found boxcryptor to better for encryption in various terms of confidentiality, availability, reliability and ease of use. All the cryptools have the same algoriths in common, i.e., the RSA for key encryprion and AES for file encryption.