SiRiUS: Securing Remote Untrusted Storage

Authors: Eu-Jin Goh, Hovav Shacham, Nagendra Modadugu, and Dan Boneh


This paper presents SiRiUS, a secure file system designed to be layered over insecure network and P2P file systems such as NFS, CIFS, OceanStore, and Yahoo! Briefcase. SiRiUS assumes the network storage is untrusted and provides its own read-write cryptographic access control for file level sharing. Key management and revocation is simple with minimal out-of-band communication. File system freshness guarantees are supported by SiRiUS using hash tree constructions. SiRiUS contains a novel method of performing file random access in a cryptographic file system without the use of a block server. Extensions to SiRiUS include large scale group sharing using the NNL key revocation construction. Our implementation of SiRiUS performs well relative to the underlying file system despite using cryptographic operations.

In the proceedings of the Internet Society (ISOC) Network and Distributed Systems Security (NDSS) Symposium 2003.
BibTex: bib

Full Paper:
Published 6th Feb 2003. Last updated 16th May 2003. ps

NDSS 2003. pdf

Related Papers: