• 
    

    
    

      99热精品在线国产_美女午夜性视频免费_国产精品国产高清国产av_av欧美777_自拍偷自拍亚洲精品老妇_亚洲熟女精品中文字幕_www日本黄色视频网_国产精品野战在线观看

      ?

      數(shù)據(jù)存儲(chǔ)在云端有多安全?

      2020-08-28 11:33張海濱
      英語(yǔ)世界 2020年8期
      關(guān)鍵詞:密鑰服務(wù)商解密

      張海濱

      As cloud storage becomes more common, data security is an increasing concern. Companies and schools have been increasing their use of services like Google Drive for some time, and lots of individual users also store files on Dropbox, Box, Amazon Drive, Microsoft OneDrive and the like. Theyre no doubt concerned about keeping their information private—and millions more users might store data online if they were more certain of its security.

      Data stored in the cloud is nearly always stored in an encrypted form that would need to be cracked before an intruder could read the information. But as a scholar of cloud computing and cloud security, Ive seen that where the keys to that encryption are held varies among cloud storage services. In addition, there are relatively simple ways users can boost their own datas security beyond whats built into systems they use.

      Who holds the keys?

      Commercial cloud storage systems encode each users data with a specific encryption key. Without it, the files look like gibberish—rather than meaningful data.

      But who has the key? It can be stored either by the service itself, or by individual users. Most services keep the key themselves, letting their systems see and process user data, such as indexing data for future searches. These services also access the key when a user logs in with a password, unlocking the data so the person can use it. This is much more convenient than having users keep the keys themselves.

      But it is also less secure: Just like regular keys, if someone else has them, they might be stolen or misused without the data owner knowing. And some services might have flaws in their security practices that leave users data vulnerable.

      Letting users keep control

      A few less popular cloud services, including Mega and SpiderOak, require users to upload and download files through service-specific client applications that include encryption functions. That extra step lets users keep the encryption keys themselves. For that additional security, users forgo some functions, such as being able to search among their cloud-stored files.

      These services arent perfect—theres still a possibility that their own apps might be compromised or hacked, allowing an intruder to read your files either before theyre encrypted for uploading or after being downloaded and decrypted. An encrypted cloud service provider could even embed functions in its specific app that could leave data vulnerable. And, of course, if a user loses the password, the data is irretrievable.

      One new mobile app says it can keep phone photos encrypted from the moment theyre taken, through transmission and storage in the cloud. Other new services may arise offering similar protection for other types of data, though users should still be on guard against the potential for information to be hijacked in the few moments after the picture is taken, before its encrypted and stored.

      Protecting yourself

      To maximize cloud storage security, its best to combine the features of these various approaches. Before uploading data to the cloud, first encrypt it using your own encryption software. Then upload the encoded file to the cloud. To get access to the file again, log in to the service, download it and decrypt it yourself.

      This, of course, prevents users from taking advantage of many cloud services, like live editing of shared documents and searching cloud-stored files. And the company providing the cloud services could still modify the data, by altering the encrypted file before you download it.

      The best way to protect against that is to use authenticated encryption. This method stores not only an encrypted file, but additional metadata that lets a user detect whether the file has been modified since it was created.

      Ultimately, for people who dont want to learn how to program their own tools, there are two basic choices: Find a cloud storage service with trustworthy upload and download software that is open-source and has been validated by independent security researchers. Or use trusted open-source encryption software to encrypt your data before uploading it to the cloud; these are available for all operating systems and are generally free or very low-cost.

      云存儲(chǔ)日益普及,人們也越來(lái)越關(guān)注數(shù)據(jù)安全。一段時(shí)間以來(lái),眾多公司和學(xué)校越來(lái)越多地使用谷歌云盤這類服務(wù),很多個(gè)人用戶也把文件存儲(chǔ)在多寶箱、Box網(wǎng)盤、亞馬遜云盤、微軟網(wǎng)盤等云服務(wù)器上。用戶無(wú)疑要關(guān)注個(gè)人信息的私密性,人們要是確信云端存儲(chǔ)的安全性,可能還會(huì)有數(shù)以百萬(wàn)計(jì)的用戶在線存儲(chǔ)數(shù)據(jù)。

      云端的數(shù)據(jù)絕大多數(shù)是以加密形式存儲(chǔ)的,入侵者若要讀取信息,必須先解密數(shù)據(jù)。我是云計(jì)算和云安全領(lǐng)域的學(xué)者,而我卻發(fā)現(xiàn)密鑰的保管地點(diǎn)因云存儲(chǔ)服務(wù)商而異。此外,除了云服務(wù)商提供的系統(tǒng)安全措施外,用戶還有一些相對(duì)簡(jiǎn)單的辦法來(lái)增強(qiáng)數(shù)據(jù)的安全性。

      密鑰由誰(shuí)保管?

      商業(yè)云存儲(chǔ)系統(tǒng)使用特定密鑰為每位用戶的數(shù)據(jù)加密。沒(méi)有密鑰,用戶文件看起來(lái)只是亂碼,而非有意義的數(shù)據(jù)。

      那么由誰(shuí)保管密鑰呢?密鑰或由服務(wù)方保管,或由個(gè)人用戶方保管。大部分服務(wù)商會(huì)自己保管密鑰,以便系統(tǒng)查看和處理用戶數(shù)據(jù),如為將來(lái)的檢索做數(shù)據(jù)索引。用戶使用密碼登錄時(shí),這些服務(wù)商也同時(shí)獲得密鑰,從而解鎖數(shù)據(jù)供該用戶使用。這種方式遠(yuǎn)比讓用戶保管密鑰方便得多。

      但這種方式的安全性要差些:和普通鑰匙一樣,要是別人也有一把,那么在主人不知情的情況下,鑰匙可能會(huì)被盜或誤用。有些服務(wù)商的安全措施可能還存在漏洞,致使用戶的數(shù)據(jù)易受攻擊。

      讓用戶掌有控制權(quán)

      包括Mega和SpiderOak在內(nèi)的幾個(gè)比較小眾的云服務(wù)商要求用戶使用有加密功能的、針對(duì)特定服務(wù)開發(fā)的客戶應(yīng)用程序來(lái)上傳和下載文件。這個(gè)額外的步驟使用戶可以自己保管密鑰。額外的安全性是用戶犧牲部分功能換來(lái)的,如在云存儲(chǔ)文件中檢索的功能。

      這些服務(wù)也并非完美無(wú)瑕,客戶應(yīng)用程序也可能被盜用或被攻擊,使入侵者可在用戶加密上傳數(shù)據(jù)之前或下載解密之后讀取文件。加密云服務(wù)供應(yīng)商在其特定應(yīng)用中嵌入的功能甚至?xí)寯?shù)據(jù)易受攻擊。而且,一旦用戶丟失密碼,數(shù)據(jù)是不可找回的。

      一款新的手機(jī)應(yīng)用宣稱,從照片拍攝開始到其在云端的傳輸、存儲(chǔ),手機(jī)照片始終處于加密狀態(tài)。為其他數(shù)據(jù)形式提供類似保護(hù)的新服務(wù)也可能會(huì)出現(xiàn),但用戶還是應(yīng)該保持警惕,在照片拍攝后、加密和存儲(chǔ)之前的片刻,信息都有被劫持的可能。

      自我保護(hù)

      為了最大化云存儲(chǔ)的安全性,我們最好是能把這幾種方法的特點(diǎn)結(jié)合起來(lái)。數(shù)據(jù)上傳之前,先用自己的加密軟件給數(shù)據(jù)加密,然后再把加密過(guò)的文件上傳到云端。再次獲取文件時(shí),登錄云服務(wù),下載后自行解密。

      當(dāng)然,這么做會(huì)妨礙用戶利用許多云服務(wù)提供的功能,如在線編輯共享文件和查找云存儲(chǔ)文件等。而且,云服務(wù)供應(yīng)商仍然可以在你下載之前通過(guò)變更加密文件來(lái)修改數(shù)據(jù)。

      最好的防范措施是使用驗(yàn)證加密。這個(gè)方法不僅存儲(chǔ)了加密文件,還另外存儲(chǔ)了元數(shù)據(jù),能讓用戶看出文件在創(chuàng)建后是否有被修改過(guò)。

      最后,給那些不想學(xué)習(xí)如何編程加密工具的人提供兩個(gè)基本選擇:找一個(gè)云服務(wù)商,其用于上傳和下載的軟件安全可靠,不僅開放源代碼,而且通過(guò)了獨(dú)立安全研究人員的驗(yàn)證;或使用值得信賴的開源加密軟件,在你把數(shù)據(jù)上傳至云端前給數(shù)據(jù)加密——所有操作系統(tǒng)都支持這兩種方法,而且一般不收費(fèi)或只收取極少費(fèi)用。

      (譯者為“《英語(yǔ)世界》杯”翻譯大賽獲獎(jiǎng)?wù)撸?/p>

      猜你喜歡
      密鑰服務(wù)商解密
      幻中邂逅之金色密鑰
      幻中邂逅之金色密鑰
      炫詞解密
      炫詞解密
      炫詞解密
      2018年全球十大IaaS服務(wù)商 中國(guó)占據(jù)四席
      BitLocker密鑰恢復(fù)二三事
      “互聯(lián)網(wǎng)+”服務(wù)商崛起
      曝阿里來(lái)往即將開放API 服務(wù)商迎新機(jī)遇
      一種新的動(dòng)態(tài)批密鑰更新算法
      绥宁县| 沾益县| 咸丰县| 微博| 通山县| 玉龙| 安新县| 白银市| 平原县| 庆云县| 佛冈县| 武宁县| 虹口区| 绥德县| 峨眉山市| 禄丰县| 龙井市| 綦江县| 新泰市| 梁山县| 鹿邑县| 庆阳市| 安西县| 永康市| 宁强县| 南华县| 仲巴县| 西吉县| 大渡口区| 九龙坡区| 景东| 德昌县| 田林县| 丹江口市| 万年县| 乡宁县| 左权县| 龙泉市| 迭部县| 昭平县| 林周县|