OblivSend: Secure and Ephemeral File Sharing Services with Oblivious Expiration Control

Yanjun Shen,Bin Yu,Shangqi Lai,Xingliang Yuan,Shi-Feng Sun,Joseph K. Liu,Surya Nepal
DOI: https://doi.org/10.1007/978-3-031-22390-7_17
2022-01-01
Abstract:Users have personal or business need to share most private and confidential documents; however, often at the expense of privacy and security. A sought after feature in the trending ephemeral context is to set download constraints of a particular file - a file can only be downloaded a limited number of times and/or for a limited period of time. Emerging end-to-end encrypted file sharing services with enhanced expiration control are attempts to meet the needs. Although such new services have drawn much attention, their server can still observe and control metadata of such download constraints, which could reveal partial data information. To address this challenge, we propose OblivSend, a privacy-preserving file sharing web service that 1) supports end-to-end encryption, 2) allows a limited period of time and a limited number of downloads at users' control, and 3) protects expiration control metadata from the server efficiently by lightweight cryptographic primitives. We develop a proof of concept prototype implemented in Hyperledger Fabric on a Research Cloud and evaluations demonstrate that our prototype can function as intended to achieve privacy of metadata without sacrificing user experience.
What problem does this paper attempt to address?