@inproceedings{TajanWesthoffArmknechtetal.2016, author = {Louis Tajan and Dirk Westhoff and Frederik Armknecht and Christian A. Reuter}, title = {Private information retrieval and Searchable Encryption for privacy-preserving multi-client cloud auditing}, series = {2016 11th International Conference for Internet Technology and Secured Transactions (ICITST)}, publisher = {IEEE}, isbn = {978-1-908320-73-5 (Elektronisch)}, doi = {10.1109/ICITST.2016.7856690}, pages = {162 -- 169}, year = {2016}, abstract = {In the work at hand, we combine a Private Information Retrieval (PIR) protocol with Somewhat Homomorphic Encryption (SHE) and use Searchable Encryption (SE) with the objective to provide security and confidentiality features for a third party cloud security audit. During the auditing process, a third party auditor will act on behalf of a cloud service user to validate the security requirements performed by a cloud service provider. Our concrete contribution consists of developing a PIR protocol which is proceeding directly on a log database of encrypted data and allowing to retrieve a sum or a product of multiple encrypted elements. Subsequently, we concretely apply our new form of PIR protocol to a cloud audit use case where searchable encryption is employed to allow additional confidentiality requirements to the privacy of the user. Exemplarily we are considering and evaluating an audit of client accesses to a controlled resource provided by a cloud service provider.}, language = {en} }