{"title":"公共云之上的Web应用安全","authors":"M. S, Gokula Santhiya R, Jeni V, Joshika Bhavna J","doi":"10.1109/ICPS55917.2022.00045","DOIUrl":null,"url":null,"abstract":"The prevalence of Microservices has made it quintessential to build web applications in a Cloud-Native fashion. While building applications in a cloud-native way, almost the entire infrastructure of an organization relies on an arbitrary Cloud Service Provider’s data center as the individual components of the organization’s on-premise infrastructure are morphed into the modern Infrastructure as a Service(IaaS) model in pay-as-you-go strategy. In this scenario, every Cloud Service Provider(CSP) ensures that they are responsible for securing the data at rest. But the data in transit is left to the user’s responsibility. Some prominent Cloud Service Providers offer services to encrypt the data in-transit as well. But under such circumstances, a copy of our enciphering keys are in any way kept under their premises which in turn is undesirable for many individual users and organizations. So, the solution is to do Client Side Encryption(CSE) to ensure the security ourselves. We are proposing a cryptosystem such that it solidifies the integrity of in-transit data by implementing the Homomorphic encryption technique using a modified form of RSA algorithm. (A study on in-flight data security using cloud services is also done.)","PeriodicalId":263404,"journal":{"name":"2022 Second International Conference on Interdisciplinary Cyber Physical Systems (ICPS)","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Web Application Security on Top of Public Cloud\",\"authors\":\"M. S, Gokula Santhiya R, Jeni V, Joshika Bhavna J\",\"doi\":\"10.1109/ICPS55917.2022.00045\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The prevalence of Microservices has made it quintessential to build web applications in a Cloud-Native fashion. While building applications in a cloud-native way, almost the entire infrastructure of an organization relies on an arbitrary Cloud Service Provider’s data center as the individual components of the organization’s on-premise infrastructure are morphed into the modern Infrastructure as a Service(IaaS) model in pay-as-you-go strategy. In this scenario, every Cloud Service Provider(CSP) ensures that they are responsible for securing the data at rest. But the data in transit is left to the user’s responsibility. Some prominent Cloud Service Providers offer services to encrypt the data in-transit as well. But under such circumstances, a copy of our enciphering keys are in any way kept under their premises which in turn is undesirable for many individual users and organizations. So, the solution is to do Client Side Encryption(CSE) to ensure the security ourselves. We are proposing a cryptosystem such that it solidifies the integrity of in-transit data by implementing the Homomorphic encryption technique using a modified form of RSA algorithm. (A study on in-flight data security using cloud services is also done.)\",\"PeriodicalId\":263404,\"journal\":{\"name\":\"2022 Second International Conference on Interdisciplinary Cyber Physical Systems (ICPS)\",\"volume\":\"19 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-05-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 Second International Conference on Interdisciplinary Cyber Physical Systems (ICPS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICPS55917.2022.00045\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 Second International Conference on Interdisciplinary Cyber Physical Systems (ICPS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICPS55917.2022.00045","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
The prevalence of Microservices has made it quintessential to build web applications in a Cloud-Native fashion. While building applications in a cloud-native way, almost the entire infrastructure of an organization relies on an arbitrary Cloud Service Provider’s data center as the individual components of the organization’s on-premise infrastructure are morphed into the modern Infrastructure as a Service(IaaS) model in pay-as-you-go strategy. In this scenario, every Cloud Service Provider(CSP) ensures that they are responsible for securing the data at rest. But the data in transit is left to the user’s responsibility. Some prominent Cloud Service Providers offer services to encrypt the data in-transit as well. But under such circumstances, a copy of our enciphering keys are in any way kept under their premises which in turn is undesirable for many individual users and organizations. So, the solution is to do Client Side Encryption(CSE) to ensure the security ourselves. We are proposing a cryptosystem such that it solidifies the integrity of in-transit data by implementing the Homomorphic encryption technique using a modified form of RSA algorithm. (A study on in-flight data security using cloud services is also done.)