OmniShare: Securely Accessing Encrypted Cloud Storage from Multiple Authorized Devices
Andrew Paverd, Sandeep Tamrakar, Hoang Long Nguyen, Praveen Kumar, Pendyala, Thien Duc Nguyen, Elizabeth Stobert, Tommi Gr\"ondahl, N. Asokan,, Ahmad-Reza Sadeghi

TL;DR
OmniShare enables secure, client-side encrypted cloud storage access across multiple devices using high-entropy keys and out-of-band device authentication, addressing privacy and usability concerns.
Contribution
It introduces a novel key distribution scheme using low-bandwidth OOB channels and a directory-based key hierarchy for secure multi-device access.
Findings
Security verified with formal methods
Achieves efficient performance in real-world benchmarks
Demonstrates usability through cognitive walkthrough
Abstract
Cloud storage services like Dropbox and Google Drive are widely used by individuals and businesses. Two attractive features of these services are 1) the automatic synchronization of files between multiple client devices and 2) the possibility to share files with other users. However, privacy of cloud data is a growing concern for both individuals and businesses. Encrypting data on the client-side before uploading it is an effective privacy safeguard, but it requires all client devices to have the decryption key. Current solutions derive these keys solely from user-chosen passwords, which have low entropy and are easily guessed. We present OmniShare, the first scheme to allow client-side encryption with high-entropy keys whilst providing an intuitive key distribution mechanism to enable access from multiple client devices. Instead of passwords, we use low bandwidth uni-directional…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Cryptography and Data Security · Advanced Authentication Protocols Security
