首页> 外文会议>IEEE Computer Security Foundations Symposium >Cryptographic Enforcement of Language-Based Information Erasure
【24h】

Cryptographic Enforcement of Language-Based Information Erasure

机译:基于语言的信息擦除的密码执行

获取原文

摘要

Information erasure is a formal security requirement that stipulates when sensitive data must be removed from computer systems. In a system that correctly enforces erasure requirements, an attacker who observes the system after sensitive data is required to have been erased cannot deduce anything about the data. Practical obstacles to enforcing information erasure include: (1) correctly determining which data requires erasure, and (2) reliably deleting potentially large volumes of data, despite untrustworthy storage services. In this paper, we present a novel formalization of language-based information erasure that supports cryptographic enforcement of erasure requirements: sensitive data is encrypted before storage, and upon erasure, only a relatively small set of decryption keys needs to be deleted. This cryptographic technique has been used by a number of systems that implement data deletion to allow the use of untrustworthy storage services. However, these systems provide no support to correctly determine which data requires erasure, nor have the formal semantic properties of these systems been explained or proven to hold. We address these shortcomings. Specifically, we study a programming language extended with primitives for public-key cryptography, and demonstrate how information-flow control mechanisms can automatically track data that requires erasure and provably enforce erasure requirements even when programs employ cryptographic techniques for erasure.
机译:信息擦除是一项正式的安全要求,其中规定了何时必须从计算机系统中删除敏感数据。在正确执行擦除要求的系统中,攻击者在要求删除敏感数据后观察该系统,无法推断出有关该数据的任何内容。实施信息擦除的实际障碍包括:(1)正确确定哪些数据需要擦除,以及(2)尽管存储服务不可靠,但仍可靠地删除了潜在的大量数据。在本文中,我们提出了一种新的基于语言的信息擦除形式化,该形式支持擦除要求的密码实施:敏感数据在存储之前已加密,并且在擦除时仅需要删除相对较小的解密密钥集。这种加密技术已被许多实现数据删除的系统所使用,以允许使用不可靠的存储服务。但是,这些系统没有提供支持来正确确定哪些数据需要擦除,也没有解释或证明这些系统的形式语义属性正确无误。我们解决了这些缺点。具体来说,我们研究了一种扩展了用于公钥密码的原语的编程语言,并演示了信息流控制机制如何自动跟踪需要擦除的数据,并且即使程序采用加密技术进行擦除也可证明其强制执行擦除要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号