Desain dan Implementasi Sistem Penyimpanan Awan dengan Zero-Knowledge End-to-End Encryption

Pratama, Johannes Daniswara (2026) Desain dan Implementasi Sistem Penyimpanan Awan dengan Zero-Knowledge End-to-End Encryption. Other thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 5025221276-Undergraduate_Thesis.pdf] Text
5025221276-Undergraduate_Thesis.pdf - Accepted Version
Restricted to Repository staff only

Download (18MB) | Request a copy

Abstract

Peningkatan penggunaan layanan penyimpanan awan membuat isu keamanan dan privasi data menjadi semakin penting. Pada sebagian besar layanan cloud, data pengguna masih berpotensi diakses oleh penyedia layanan karena proses enkripsi dan pengelolaan kunci belum sepenuhnya dilakukan di sisi pengguna. Kondisi ini dapat menimbulkan risiko kebocoran data, terutama pada data yang bersifat sensitif. Penelitian ini merancang dan mengimplementasikan sistem penyimpanan awan dengan pendekatan zero-knowledge end-to-end encryption, yaitu sistem yang seluruh proses enkripsi, dekripsi, dan pengelolaan kuncinya dilakukan di sisi client. Sistem menggunakan VOPRF sebagai pseudorandom function (PRF), Argon2id dan HKDF sebagai key derivation function (KDF), serta algoritma authenticated encryption with associated data (AEAD) yang terdiri atas AEGIS-256, AES-GCM-256, dan ChaCha20-Poly1305. Ketiga algoritma tersebut diterapkan secara terpisah pada setiap skenario pengujian. Penelitian ini juga menerapkan metode chunking dan mengevaluasi dampaknya terhadap penggunaan memori serta waktu pemrosesan pada operasi pengunggahan (push) dan pengunduhan (pull). Hasil pengujian menunjukkan bahwa penerapan enkripsi secara umum menghasilkan rata-rata elapsed time dan process CPU time yang lebih tinggi dibandingkan kondisi tanpa enkripsi. Pada lingkungan pengujian yang digunakan, AEGIS-256 secara umum cenderung menghasilkan nilai rata-rata elapsed time dan process CPU time yang lebih rendah dibandingkan AES-GCM-256 dan ChaCha20-Poly1305 pada berkas berukuran 50 MiB dan 500 MiB. Dibandingkan metode non-chunking, metode chunking cenderung menghasilkan elapsed time yang lebih rendah, sekaligus mampu menjaga penggunaan memori tetap rendah.
================================================================================================================================
The increasing use of cloud storage services has raised serious concerns regarding data security and user privacy. In many existing cloud solutions, service providers may still have access to user data because encryption and key management processes are not yet fully performed on the user side. This condition may create a risk of data leakage, particularly for sensitive data. This research designs and implements a cloud storage system based on a zero-knowledge end-to-end encryption approach, in which all encryption, decryption, and key management processes are performed on the client side. The system uses VOPRF as a pseudorandom function (PRF), Argon2id and HKDF as key derivation functions (KDFs), and three authenticated encryption with associated data (AEAD) algorithms: AEGIS-256, AES-GCM-256, and ChaCha20-Poly1305. The three algorithms are applied separately in each test scenario. This research also implements a chunking method and evaluates its impact on memory usage and processing time during upload (push) and download (pull) operations. The test results show that encryption generally produces higher mean elapsed time and process CPU time than the unencrypted condition. In the evaluated environment, AEGIS-256 generally produces lower mean elapsed time and process CPU time than AES-GCM-256 and ChaCha20-Poly1305 for 50 MiB and 500 MiB files. Compared with the non-chunking method, the chunking method tends to produce lower elapsed time while maintaining low memory usage.

Item Type: Thesis (Other)
Uncontrolled Keywords: Cloud Storage, Zero-Knowledge End-to-End Encryption, VOPRF, Argon2id, AEGIS, AES-GCM, ChaCha20-Poly1305
Subjects: Q Science > QA Mathematics > QA76.585 Cloud computing. Mobile computing.
Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science)
Q Science > QA Mathematics > QA76.9.C55 Client/server computing
T Technology > TK Electrical engineering. Electronics Nuclear engineering > TK5102.94 Cryptographic techniques
Divisions: Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis
Depositing User: JOHANNES DANISWARA PRATAMA
Date Deposited: 28 Jul 2026 08:01
Last Modified: 29 Jul 2026 02:25
URI: http://repository.its.ac.id/id/eprint/137734

Actions (login required)

View Item View Item