DocumentCode :
3592164
Title :
Network-level privacy for hosted cloud services
Author :
Natarajan, Sriram ; Wolf, Tilman
Author_Institution :
R&D Lab., Deutsche Telekom Inc., USA
fYear :
2014
Firstpage :
1
Lastpage :
8
Abstract :
Cloud infrastructure providers allow multiple services to be hosted on a shared physical infrastructure. In a typical virtualized and multi-tenant environment, the cloud infrastructure and the hosted cloud services are managed by different administrative entities that may not trust each other. In such a scenario, the cloud service providers might hesitate to disclose operational information to the infrastructure providers. In this paper, we present Encrypted IP (EncrIP), a network-level design consideration for encrypting IP addresses that hides information about which end-systems are communicating in a cloud service, while still allowing packet forwarding with longest-prefix match in commodity routers. Using probabilistic encryption, EncrIP can avoid that an observer can identify what traffic belongs to the same source-destination pairs. Our evaluation results show that EncrIP requires only a few MB of memory on the gateways where traffic enters and leaves the cloud network infrastructure. In our prototype implementation of EncrIP on GENI, which uses standard IP headers, the success probability of a statistical inference attack to identify packets belonging to the same session is less than 0.001%. Therefore, we believe EncrIP presents a practical solution for protecting privacy in multi-tenant, cloud network infrastructure.
Keywords :
IP networks; cloud computing; computer network security; cryptography; data privacy; probability; telecommunication traffic; virtualisation; EncrIP; IP address encryption; cloud infrastructure providers; cloud service providers; commodity routers; encrypted IP; gateways; hosted cloud services; longest-prefix match; multitenant cloud network infrastructure; multitenant environment; network-level design; network-level privacy; packet forwarding; privacy protection; probabilistic encryption; shared physical infrastructure; source-destination pairs; standard IP headers; statistical inference attack; success probability; virtualized environment; Encryption; Logic gates; Protocols; Routing; Secure storage;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network of the Future (NOF), 2014 International Conference and Workshop on the
Type :
conf
DOI :
10.1109/NOF.2014.7119797
Filename :
7119797
Link To Document :
بازگشت