OblivSend: secure and ephemeral file sharing services with oblivious expiration control

Yanjun Shen, Bin Yu, Shangqi Lai, Xingliang Yuan, Shi-Feng Sun, Joseph K. Liu, Surya Nepal

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

1 Citation (Scopus)

Abstract

Users have personal or business need to share most private and confidential documents; however, often at the expense of privacy and security. A sought after feature in the trending ephemeral context is to set download constraints of a particular file - a file can only be downloaded a limited number of times and/or for a limited period of time. Emerging end-to-end encrypted file sharing services with enhanced expiration control are attempts to meet the needs. Although such new services have drawn much attention, their server can still observe and control metadata of such download constraints, which could reveal partial data information. To address this challenge, we propose OblivSend, a privacy-preserving file sharing web service that 1) supports end-to-end encryption, 2) allows a limited period of time and a limited number of downloads at users’ control, and 3) protects expiration control metadata from the server efficiently by lightweight cryptographic primitives. We develop a proof of concept prototype implemented in Hyperledger Fabric on a Research Cloud and evaluations demonstrate that our prototype can function as intended to achieve privacy of metadata without sacrificing user experience.

Original languageEnglish
Title of host publicationInformation Security - 25th International Conference, ISC 2022 Bali, Indonesia, December 18–22, 2022 Proceedings
EditorsWilly Susilo, Xiaofeng Chen, Fuchun Guo, Yudi Zhang, Rolly Intan
Place of PublicationCham Switzerland
PublisherSpringer
Pages269-289
Number of pages21
ISBN (Electronic)9783031223907
ISBN (Print)9783031223891
DOIs
Publication statusPublished - 2022
EventInformation Security Conference 2022 - Bali, Indonesia
Duration: 18 Dec 202222 Dec 2022
Conference number: 25th
https://link.springer.com/book/10.1007/978-3-031-22390-7 (Proceedings)
https://isc2022.petra.ac.id/ (Website)

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume13640
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInformation Security Conference 2022
Abbreviated titleISC 2022
Country/TerritoryIndonesia
CityBali
Period18/12/2222/12/22
Internet address

Keywords

  • Metadata protection
  • Privacy-preserving protocols
  • Security and privacy protection
  • Smart contract
  • Web application security

Cite this