There is an increasing number of easy-to-use cloud services to store and share information with others. Facebook, Dropbox, iCloud, Googlemail, Amazon S3, Windows SkyDrive and similar services encourage users to entrust the companies' servers with a large variety of information: from their holiday pictures to corporate documents. However, both private and corporate users commonly fail to take account of possible privacy consequences. Even though there are approaches to provide confidentiality for the users' data in the cloud, these are not widely adopted due to both awareness and usability issues. Therefore, we propose the novel Confidentiality as a Service (CaaS) paradigm to provide usable confidentiality and integrity for the bulk of users, for whom the current security mechanisms are too complex or require too much effort. The CaaS paradigm combines data security with usability by design and integrates effortlessly into available cloud service applications and workflows. We leverage the splitting of trust between the cloud service provider and one or more CaaS providers to improve usability. CaaS focuses on unobtrusive confidentiality by hiding all cryptographic artefacts from the prevalently non-technical users. Data protection is based on symmetric encryption and invisible key-management mechanisms. We present an integration for multiple popular cloud services to demonstrate the seamless applicability of CaaS.
Description
IEEE Xplore - Confidentiality as a Service -- Usable Security for the Cloud
%0 Conference Paper
%1 6295970
%A Fahl, S.
%A Harbach, M.
%A Muders, T.
%A Smith, M.
%B Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
%D 2012
%K 2012 cloud confidentiality dropbox encryption facebook myown networks social usability
%P 153 -162
%R 10.1109/TrustCom.2012.112
%T Confidentiality as a Service -- Usable Security for the Cloud
%U http://ieeexplore.ieee.org/xpls/abs_all.jsp?arnumber=6295970
%X There is an increasing number of easy-to-use cloud services to store and share information with others. Facebook, Dropbox, iCloud, Googlemail, Amazon S3, Windows SkyDrive and similar services encourage users to entrust the companies' servers with a large variety of information: from their holiday pictures to corporate documents. However, both private and corporate users commonly fail to take account of possible privacy consequences. Even though there are approaches to provide confidentiality for the users' data in the cloud, these are not widely adopted due to both awareness and usability issues. Therefore, we propose the novel Confidentiality as a Service (CaaS) paradigm to provide usable confidentiality and integrity for the bulk of users, for whom the current security mechanisms are too complex or require too much effort. The CaaS paradigm combines data security with usability by design and integrates effortlessly into available cloud service applications and workflows. We leverage the splitting of trust between the cloud service provider and one or more CaaS providers to improve usability. CaaS focuses on unobtrusive confidentiality by hiding all cryptographic artefacts from the prevalently non-technical users. Data protection is based on symmetric encryption and invisible key-management mechanisms. We present an integration for multiple popular cloud services to demonstrate the seamless applicability of CaaS.
@inproceedings{6295970,
abstract = {There is an increasing number of easy-to-use cloud services to store and share information with others. Facebook, Dropbox, iCloud, Googlemail, Amazon S3, Windows SkyDrive and similar services encourage users to entrust the companies' servers with a large variety of information: from their holiday pictures to corporate documents. However, both private and corporate users commonly fail to take account of possible privacy consequences. Even though there are approaches to provide confidentiality for the users' data in the cloud, these are not widely adopted due to both awareness and usability issues. Therefore, we propose the novel Confidentiality as a Service (CaaS) paradigm to provide usable confidentiality and integrity for the bulk of users, for whom the current security mechanisms are too complex or require too much effort. The CaaS paradigm combines data security with usability by design and integrates effortlessly into available cloud service applications and workflows. We leverage the splitting of trust between the cloud service provider and one or more CaaS providers to improve usability. CaaS focuses on unobtrusive confidentiality by hiding all cryptographic artefacts from the prevalently non-technical users. Data protection is based on symmetric encryption and invisible key-management mechanisms. We present an integration for multiple popular cloud services to demonstrate the seamless applicability of CaaS.},
added-at = {2012-11-14T19:23:57.000+0100},
author = {Fahl, S. and Harbach, M. and Muders, T. and Smith, M.},
biburl = {https://www.bibsonomy.org/bibtex/27dc3c792973659e56bb783cd0d71351c/harbach},
booktitle = {Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on},
description = {IEEE Xplore - Confidentiality as a Service -- Usable Security for the Cloud},
doi = {10.1109/TrustCom.2012.112},
interhash = {7f795ca083179ec342950a08d48d8a20},
intrahash = {7dc3c792973659e56bb783cd0d71351c},
keywords = {2012 cloud confidentiality dropbox encryption facebook myown networks social usability},
month = {june},
pages = {153 -162},
timestamp = {2012-11-14T19:23:57.000+0100},
title = {Confidentiality as a Service -- Usable Security for the Cloud},
url = {http://ieeexplore.ieee.org/xpls/abs_all.jsp?arnumber=6295970},
year = 2012
}