Confidential and Verifiable Data Storage in the Distributed Cloud
D-36
Doctorate Full Doctorate
- Disciplines
- Laboratory
- BORDEAUX LABORATORY FOR INFORMATICS RESEARCH (LABRI)
- Host institution
- Université de Bordeaux
- Doctoral school
- Doctoral school for Mathematics and Computer Science - ED 39
Description
The trend toward outsourcing data storage to the cloud has increased sharply in recent years, including for highly sensitive data such as medical and financial records. This model offers elasticity, resource sharing, and cost reduction, but it also raises major security concerns. Recent history has shown numerous data breaches affecting cloud infrastructures, often caused either by malicious insiders (employees, administrators) or by exploits targeting the lowest software layers. This situation undermines users trust in cloud providers and makes it crucial to guarantee data confidentiality (protection against any unauthorized access), integrity (prevention and detection of unwanted modifications), and auditability (the ability to verify, after the fact, compliance with access policies and the absence of fraud).Ensuring reliable storage of sensitive data in an uncontrolled distributed cloud environment is a complex challenge. Existing solutions often rely on strong trust assumptions regarding the server, or on a limited adversarial model (honest-but-curious behavior, no active attacks, etc.). In practice, however, these assumptions may no longer hold when the provider itself is compromised. The research question can therefore be stated as follows: how can confidential data be stored and managed on potentially untrusted cloud servers while guaranteeing end-to-end confidentiality, integrity, and auditability? Addressing this question requires rethinking classical approaches by relying on cryptographic techniques and innovative systems mechanisms.
The ultimate goal of this PhD project is to design a new distributed cloud storage architecture combining trusted hardware and advanced cryptography, together with a comprehensive analysis of its security guarantees (formal proofs or arguments) and a solid experimental validation on representative use cases. This dual approach, both theoretical and practical, will make it possible to produce results that are valuable both for the scientific community (new primitives, publications) and for the cloud industry seeking solutions to protect sensitive data.
Skills required
Strong understanding of cloud, storage and secure distributed systems Proficiency in algorithm design and applied cryptography Experience in programming languages such as Python, C++, Rust or Golang Research skills including literature review, data analysis, and academic writing Excellent verbal and written communication skills Ability to work independently and as part of a team Master's degree in Computer Science, Information Technology, or related field Prior research experience in cloud storage, systems or distributed systems is a plusBibliography
[1] Beimel, A. (2011, May). Secret-sharing schemes: A survey. In International conference on coding and cryptology (pp. 11-46). Berlin, Heidelberg: Springer Berlin Heidelberg.[2] Costan, V., & Devadas, S. (2016). Intel SGX explained. Cryptology ePrint Archive
[3] Stefan Contiu, Laurent Reveillère, Etienne Rivière (2020). Practical Active Revocation. Middleware 2020.
[4] Cachin, C., & Tessaro, S. (2005, October). Asynchronous verifiable information dispersal. In 24th IEEE Symposium on Reliable Distributed Systems (SRDS'05) (pp. 191-201). IEEE
[5] Goldwasser, S., Micali, S., & Rackoff, C. (2019). The knowledge complexity of interactive proof-systems. In Providing sound foundations for cryptography: On the work of shafi goldwasser and silvio micali (pp. 203-225)
[6] Zhou, L., Diro, A., Saini, A., Kaisar, S., & Hiep, P. C. (2024). Leveraging zero knowledge proofs for blockchain-based identity sharing: A survey of advancements, challenges and opportunities. Journal of Information Security and Applications, 80, 103678
[7] Yuncong Hu et al. (2020). Ghostor: Toward a Secure Data-Sharing System from Decentralized Trust. NSDI 20.
[8] Cappello, F., Caron, E., Dayde, M., Desprez, F., Jégou, Y., Primet, P., ... & Richard, O. (2005, November). Grid'5000: A large scale and highly reconfigurable grid experimental testbed. In The 6th IEEE/ACM International Workshop on Grid Computing, 2005. (pp. 8-pp). IEEE
【9】 Yuncong Hu et al. (2020). Ghostor: Toward a Secure Data-Sharing System from Decentralized Trust. NSDI 20.
【10】 Wang et al. (2012). Public Auditing for Ensuring Cloud Data Storage Security With Zero Knowledge Privacy. Cryptology ePrint Archive.
Keywords
Storage, Zero Knowledge proog, Distributed systems, Cloud, Secret sharing, Trusted execution environmentFunded offer
Dates
Application deadline 30/09/26
Duration36 months
Start date01/10/26
Creation date08/05/26
Languages
Level of french requiredB2 (upper-intermediate)
Level of English requiredB2 (upper-intermediate)
Miscellaneous
Annual tuition fee400 € / year
Contacts
You must connect to be able to display the contacts.
