首页> 外文会议>International Symposium on Resilient Control Systems >The case for distributed data archival using secret splitting with Percival
【24h】

The case for distributed data archival using secret splitting with Percival

机译:使用Percival的分布式数据档案的案例

获取原文

摘要

Most encryption used today obfuscates data behind a secret key or a problem believed to be computationally complex. One can fundamentally think of it as delayed release for a determined adversary. This approach is not well suited for long-term archival of sensitive data. Additionally, issues such as key rotation, and lost or exposed keys, make keeping such archives up to date very difficult. As a result most become static and unable to respond to attacks. Once hacked, such systems offer little to no protection for data privacy and leave open uncertainty about data integrity. Given the increasing frequency of major cyber events these days, it is clear that any secure long-term archive needs to be able to address maintaining data privacy and integrity throughout a compromise event. In spite of these needs, most data archives today still use central storage servers and encryption. In this paper we make the case for secure data archival based on secret splitting and distributed data repositories. We present Percival, one example of a research project focused on long-term data archival using Shamir's secret splitting and distributed data repositories. We examine how this approach can continue secure operations in the presence of adversarial compromise. We discuss how this distributed model significantly increases the attacker's burden by requiring the compromise of many sites. Additionally, this approach increases the resilience to insider threat and provides stronger assurances of data integrity and confidentiality. Finally we discuss current research to create new capabilities that enable blinded search across such an archive.
机译:今天使用的大多数加密都使用秘密密钥背后的数据或者被认为是计算复杂的问题。人们可以从根本上将其视为坚定的对手的延迟释放。这种方法并不适用于敏感数据的长期存档。此外,键旋转和丢失或暴露键等问题使得迄今为止保持此类档案非常困难。结果最为静态,无法响应攻击。一旦被黑客攻击,这种系统就没有对数据隐私的影响很少,并留下对数据完整性的开放不确定性。鉴于这些天主要网络事件的频率增加,很明显,任何安全的长期存档都需要能够在整个妥协事件中解决维护数据隐私和完整性。尽管有这些需求,但今天的大多数数据档案仍然使用中央存储服务器和加密。在本文中,我们将基于秘密分割和分布式数据存储库进行安全数据档案的情况。我们呈现Percival,一个研究项目的一个例子专注于使用Shamir的秘密分裂和分布式数据存储库的长期数据档案。我们研究这种方法如何在存在对抗妥协的情况下继续安全操作。我们讨论这种分布式模型如何通过要求许多网站的妥协来显着提高攻击者的负担。此外,这种方法增加了对内部威胁的弹性,并提供了更强的数据完整性和机密性的保证。最后,我们讨论了当前的研究,以创建新的功能,使盲目搜索在此类存档中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号