Privacy-Preserving Efficient Verifiable Deep Packet Inspection for Cloud-Assisted Middlebox

被引:30
|
作者
Ren, Hao [1 ,2 ]
Li, Hongwei [1 ,2 ]
Liu, Dongxiao [3 ]
Xu, Guowen [1 ]
Cheng, Nan [4 ]
Shen, Xuemin [3 ]
机构
[1] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu 611731, Peoples R China
[2] Peng Cheng Lab, Cyberspace Secur Res Ctr, Shenzhen 518066, Guangdong, Peoples R China
[3] Univ Waterloo, Dept Elect & Comp Engn, Waterloo, ON N2L 3G1, Canada
[4] Xidian Univ, Sch Telecommun Engn, Xian 710071, Shanxi, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Cloud computing; middlebox; network function outsourcing; privacy-preserving; RANGE QUERY; SECURE;
D O I
10.1109/TCC.2020.2991167
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the increasing traffic volume, enterprises choose to outsource their middlebox services, such as deep packet inspection, to the cloud to acquire rich computational and communication resources. However, since the traffic is redirected to the public cloud, information leakages, such as packet payload and inspection rules, arouse privacy concerns of both middlebox owner and packet senders. To address the concerns, we propose an efficient verifiable deep packet inspection (EV-DPI) scheme with strong privacy guarantees. Specifically, a two-layer architecture is designed and deployed over two non-collusion cloud servers. The first layer fast filters out most of legitimate packets and the second layer supports exact rule matching. During the inspection, the privacy of packet payload and the confidentiality of inspection rules are well preserved. To improve the efficiency, only fast symmetric crypto-systems, such as hash functions, are used. Moreover, the proposed scheme allows the network administrator to verify the execution results, which offers a strong control of outsourced services. To validate the performance of the proposed EV-DPI scheme, we conduct extensive experiments on the Amazon Cloud. Large-scale dataset (millions of packets) is tested to obtain the key performance metrics. The experimental results demonstrate that EV-DPI not only preserves the packet privacy, but also achieves high packet inspection efficiency.
引用
收藏
页码:1052 / 1064
页数:13
相关论文
共 50 条
  • [21] SPABox: Safeguarding Privacy During Deep Packet Inspection at a MiddleBox
    Fan, Jingyuan
    Guan, Chaowen
    Ren, Kui
    Cui, Yong
    Qiao, Chunming
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (06) : 3753 - 3766
  • [22] Privacy-enhanced Deep Packet Inspection at Outsourced Middlebox
    Li, Hongwei
    Ren, Hao
    Liu, Dongxiao
    Shen, Xuemin
    2018 10TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS AND SIGNAL PROCESSING (WCSP), 2018,
  • [23] Enabling Secure Intelligent Network with Cloud-Assisted Privacy-Preserving Machine Learning
    Yu, Yong
    Li, Huilin
    Chen, Ruonan
    Zhao, Yanqi
    Yang, Haomiao
    Du, Xiaojiang
    IEEE NETWORK, 2019, 33 (03): : 82 - 87
  • [24] PPDM: A Privacy-Preserving Protocol for Cloud-Assisted e-Healthcare Systems
    Zhou, Jun
    Cao, Zhenfu
    Dong, Xiaolei
    Lin, Xiaodong
    IEEE JOURNAL OF SELECTED TOPICS IN SIGNAL PROCESSING, 2015, 9 (07) : 1332 - 1344
  • [25] PPRU: A Privacy-Preserving Reputation Updating Scheme for Cloud-Assisted Vehicular Networks
    Liu, Zhiquan
    Wan, Lin
    Guo, Jingjing
    Huang, Feiran
    Feng, Xia
    Wang, Libo
    Ma, Jianfeng
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2025, 74 (02) : 1877 - 1892
  • [26] Secure and Privacy-Preserving Warning Message Dissemination in Cloud-Assisted Internet of Vehicles
    Huang, Qinlong
    Li, Nan
    Zhang, Zhicheng
    Yang, Yixian
    2019 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2019,
  • [27] Healthcare Applications Using Blockchain With a Cloud-Assisted Decentralized Privacy-Preserving Framework
    Deebak, Bakkiam David
    Hwang, Seong Oun
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (05) : 5897 - 5916
  • [28] P2DPI: Practical and Privacy-Preserving Deep Packet Inspection
    Kim, Jongkil
    Camtepe, Seyit
    Baek, Joonsang
    Susilo, Willy
    Pieprzyk, Josef
    Nepal, Surya
    ASIA CCS'21: PROCEEDINGS OF THE 2021 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 135 - 146
  • [29] Towards privacy-preserving dynamic deep packet inspection over outsourced middleboxes
    Li, Chunxiao
    Guo, Yu
    Wang, Xia
    HIGH-CONFIDENCE COMPUTING, 2022, 2 (01):
  • [30] EPNS: Efficient Privacy-Preserving Intelligent Traffic Navigation From Multiparty Delegated Computation in Cloud-Assisted VANETs
    Zhou, Jun
    Chen, Shiying
    Choo, Kim-Kwang Raymond
    Cao, Zhenfu
    Dong, Xiaolei
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2023, 22 (03) : 1491 - 1506