{"title":"Recovering Private User Storages in Online Social Networks","authors":"Fabian Schillinger, C. Schindelhauer","doi":"10.20533/JITST.2046.3723.2020.0083","DOIUrl":null,"url":null,"abstract":"Private user storages are used in Online Social Networks (OSN) to securely save private settings and keys on a server. This allows users to access these settings and keys from all their devices. Therefore, private user storages can synchronize these devices. When end-to-end encryption is applied in an OSN to ensure the privacy of users and the communication private user storages can be used to safely store all private and symmetric keys. A user can retrieve the encrypted storage from the server and decrypt it with its password. However, when the password is lost access to the private user storage is lost as well, as the symmetric key cannot be retrieved from the server in contrast to the recovery functions of some OSNs, where a new password can be created. We present a scheme that splits private user storages into different parts and applies two different secret sharing schemes to be able to recover the keys with the help of the other participants of the OSN. The scheme is more robust to missing shares than other secret sharing schemes. Therefore, even when a large fraction of the distributed shares are not accessible because shareholders are inactive or malicious high rates of successful reconstructions can be achieved. Keyword send-to-end encryption, online chat; online social networ, applied secret sharing, private storage, instant messaging service","PeriodicalId":38357,"journal":{"name":"International Journal of Internet Technology and Secured Transactions","volume":"80 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2020-12-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Internet Technology and Secured Transactions","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.20533/JITST.2046.3723.2020.0083","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 2
Abstract
Private user storages are used in Online Social Networks (OSN) to securely save private settings and keys on a server. This allows users to access these settings and keys from all their devices. Therefore, private user storages can synchronize these devices. When end-to-end encryption is applied in an OSN to ensure the privacy of users and the communication private user storages can be used to safely store all private and symmetric keys. A user can retrieve the encrypted storage from the server and decrypt it with its password. However, when the password is lost access to the private user storage is lost as well, as the symmetric key cannot be retrieved from the server in contrast to the recovery functions of some OSNs, where a new password can be created. We present a scheme that splits private user storages into different parts and applies two different secret sharing schemes to be able to recover the keys with the help of the other participants of the OSN. The scheme is more robust to missing shares than other secret sharing schemes. Therefore, even when a large fraction of the distributed shares are not accessible because shareholders are inactive or malicious high rates of successful reconstructions can be achieved. Keyword send-to-end encryption, online chat; online social networ, applied secret sharing, private storage, instant messaging service
私有用户存储用于OSN (Online Social Networks)中,用于在服务器上安全地保存私有设置和密钥。这允许用户从他们所有的设备访问这些设置和密钥。因此,私有用户存储可以同步这些设备。当OSN采用端到端加密方式保证用户的隐私时,可以使用通信私钥存储安全地存储所有的私钥和对称密钥。用户可以从服务器检索加密存储并使用其密码对其进行解密。但是,当密码丢失时,由于无法从服务器检索对称密钥,因此也会丢失对私有用户存储的访问权限,而某些osn的恢复功能可以创建新密码。我们提出了一种将私有用户存储分割成不同的部分,并应用两种不同的秘密共享方案,在OSN的其他参与者的帮助下能够恢复密钥的方案。该方案对缺失股份的鲁棒性优于其他秘密共享方案。因此,即使由于股东不活跃或恶意而无法访问大部分已分配股份,也可以实现高成功重建率。关键词发送到端加密,在线聊天;在线社交网络,应用秘密共享,私人存储,即时通讯服务