DEFTL: Implementing Plausibly Deniable Encryption in Flash Translation Layer
Shijie Jia, Luning Xia, Bo Chen, Peng Liu
Abstract
Mobile devices today have been increasingly used to store and process sensitive information. To protect sensitive data, mobile operating systems usually incorporate a certain level of encryption to protect sensitive data. However, conventional encryption cannot defend against a coercive attacker who can capture the device owner, and force the owner to disclose keys used for decrypting sensitive information. To defend against such a coercive adversary, Plausibly Deniable Encryption (PDE) was introduced to allow the device owner to deny the very existence of sensitive data stored on his/her device. The existing PDE systems, built on flash storage devices, are problematic, since they either neglect the special nature of the underlying storage medium (which is usually NAND flash), or suffer from deniability compromises. In this paper, we propose DEFTL, a Deniability Enabling Flash Translation Layer for devices which use flash-based block devices as storage media. DEFTL is the first PDE design which incorporates deniability to Flash Translation Layer (FTL), a pervasively deployed "translation layer" which stays between NAND flash and the file system in literally all the computing devices. A salient advantage of DEFTL lies in its capability of achieving deniability while being able to accommodate the special nature of NAND flash as well as eliminate deniability compromises from it. We implement DEFTL using an open-source NAND flash controller. The experimental results show that, compared to conventional encryption which does not provide deniability, our DEFTL design only incurs a small overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 53d2cdd5-a8d2-489d-b515-aed25f18db1bCited by top-tier papers6
- PEARL: Plausibly Deniable Flash Translation Layer using WOM codingChen Chen, Anrin Chakraborti, Radu SionUSENIX Security 2021 · 15 citations
- Travelling the Hypervisor and SSD: A Tag-Based Approach Against Crypto Ransomware with Fine-Grained Data RecoveryBoyang Ma, Yilin Yang, Jinku Li, Fengwei Zhang et al.CCS 2023 · 10 citations
- Invisible bits: hiding secret messages in SRAM's analog domainJubayer Mahmod, Matthew HicksASPLOS 2022 · 5 citations
- Shufflecake: Plausible Deniability for Multiple Hidden Filesystems on LinuxElia Anzuoni, Tommaso GagliardoniCCS 2023 · 4 citations
- Data Recovery from "Scrubbed" NAND Flash Storage: Need for Analog SanitizationMd. Mehedi Hasan, Biswajit RayUSENIX Security 2020
Related papers
- Wink: Deniable Secure MessagingAnrin Chakraborti, Darius Suciu, Radu SionUSENIX Security 2023
- Eliminating Storage Management Overhead of Deduplication over SSD Arrays Through a Hardware/Software Co-DesignYuhong Wen, Xiaogang Zhao, You Zhou, Tong Zhang et al.ASPLOS 2024 · 7 citations
- Deniable Fully Homomorphic Encryption from Learning with ErrorsShweta Agrawal, Shafi Goldwasser, Saleet MosselCRYPTO 2021 · 18 citations
- INVISILINE: Invisible Plausibly-Deniable StorageSandeep Kiran Pinjala, Bogdan Carbunar, Anrin Chakraborti, Radu SionS&P 2024 · 3 citations
- Decoupled SSD: Rethinking SSD Architecture through Network-based Flash ControllersJiho Kim, Myoungsoo Jung, John KimISCA 2023 · 10 citations
