Securing End-to-End Encrypted File Sharing Services with the Messaging Layer Security Protocol
摘要
To protect data on the servers of cloud service providers, file-sharing services rely on End-to-End Encryption (E2EE). However, existing solutions have weaknesses that allow attackers to bypass E2EE permanently after stealing a clients keys once. In this paper, a concept for an E2EE file-sharing service is proposed which does not have this vulnerability. It is based on Messaging Layer Security (MLS) groups for key distribution, an authentication system based on asymmetric cryptography, Attribute-Based Access Control (ABAC) based access rights and a tamper-proof versioned storage system for synchronising sensitive data. The applicability of the concept is demonstrated by a prototype implementation and an evaluation based on benchmarks and a security analysis. Overall, the concept can fulfil the requirements of a basic file sharing service while providing stronger security guarantees than existing solutions.