Practical Improvements to User Privacy in Cloud Applications

dc.contributor.advisorAnderson, Thomas
dc.contributor.advisorKrishnamurthy, Arvind
dc.contributor.authorCheng, Raymond
dc.date.accessioned2017-10-26T20:48:56Z
dc.date.available2017-10-26T20:48:56Z
dc.date.issued2017-10-26
dc.date.submitted2017-08
dc.descriptionThesis (Ph.D.)--University of Washington, 2017-08
dc.description.abstractAs the cloud handles more user data, users need better techniques to protect their privacy from adversaries looking to gain unauthorized access to sensitive data. Today’s cloud services offer weak assurances with respect to user privacy, as most data is processed unencrypted in a centralized location by systems with a large trusted computing base. While current architectures enable application development speed, this comes at the cost of susceptibility to large-scale data breaches. In this thesis, I argue that we can make significant improvements to user privacy from both external attackers and insider threats. In the first part of the thesis, I develop the Radiatus architecture for securing fully-featured cloud applications from external attacks. Radiatus secures private data stored by web applications by isolating server-side code execution into per-user sandboxes, limiting the scope of successful attacks. In the second part of the thesis, I focus on a simpler messaging application, Talek, securing it from both external and insider threats. Talek is a group private messaging system that hides both message contents as well as communication patterns from an adversary in partial control of the cloud. Both of these systems are designed to provide better security and privacy guarantees for users under realistic threat models, while offering practical performance and development costs. This thesis presents an implementation and evaluation of both systems, showing that improved user privacy can come at acceptable costs.
dc.embargo.termsOpen Access
dc.format.mimetypeapplication/pdf
dc.identifier.otherCheng_washington_0250E_17770.pdf
dc.identifier.urihttp://hdl.handle.net/1773/40542
dc.language.isoen_US
dc.rightsCC BY-SA
dc.subjectcloud
dc.subjectprivacy
dc.subjectsecurity
dc.subjectComputer science
dc.subject.otherComputer science and engineering
dc.titlePractical Improvements to User Privacy in Cloud Applications
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Cheng_washington_0250E_17770.pdf
Size:
1.14 MB
Format:
Adobe Portable Document Format