2FE: Two-Factor Encryption for Cloud Storage
Anders Dalskov, Daniele Lain, Enis Ulqinaku, Kari Kostiainen, Srdjan, Capkun

TL;DR
This paper introduces 2FE, a two-factor encryption scheme for cloud storage that enhances confidentiality and availability by involving two user devices in encryption and decryption, addressing real-world threats like device theft and human errors.
Contribution
The paper proposes a novel two-factor encryption scheme that improves security and resilience of cloud storage against device compromise and user errors, using secret sharing and cryptographic techniques.
Findings
2FE provides strong confidentiality and availability guarantees.
Performance overhead of 2FE is small based on experimental evaluation.
The approach can be adapted for cryptocurrency wallets.
Abstract
Encrypted cloud storage services are steadily increasing in popularity, with many commercial solutions currently available. In such solutions, the cloud storage is trusted for data availability, but not for confidentiality. Additionally, the user's device is considered secure, and the user is expected to behave correctly. We argue that such assumptions are not met in reality: e.g., users routinely forget passwords and fail to make backups, and users' devices get stolen or become infected with malware. Therefore, we consider a more extensive threat model, where users' devices are susceptible to attacks and common human errors are possible. Given this model, we analyze 10 popular commercial services and show that none of them provides good confidentiality and data availability. Motivated by the lack of adequate solutions in the market, we design a novel scheme called Two-Factor…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Cloud Data Security Solutions · User Authentication and Security Systems
