Holepunch: Fast, Secure File Deletion with Crash Consistency
Zachary Ratliff, Wittmann Goh, Abe Wieland, James Mickens, Ryan Williams
Abstract
A file system provides secure deletion if, after a file is deleted, an attacker with physical possession of the storage device cannot recover any data from the deleted file. Unfortunately, secure deletion is not provided by commodity file systems. Even file systems which explicitly desire to provide secure deletion are challenged by the subtleties of hardware controllers on modern storage devices; those controllers obscure the mappings between logical blocks and physical blocks, silently duplicate physical blocks, and generally make it hard for host-level software to make reliable assumptions about how file data is kept on the device. State-of-the-art frameworks for secure deletion also have no crash consistency, meaning that an ill-timed power outage or software fault will desynchronize keys and the associated encrypted file data, corrupting the file system.In this paper, we present Holepunch, a new software-level approach for implementing secure deletion. Holepunch treats the storage device as a black box, providing secure deletion via cryptographic erasure. Holepunch uses per-file keys to transparently encrypt outgoing file writes and decrypt incoming file reads, ensuring that all physical data in the storage device is always encrypted. Holepunch uses puncturable pseudorandom functions (PPRFs) to quickly access file keys; upon the deletion of file f, Holepunch updates the PPRF so that, even if the PPRF is recovered, the PPRF cannot be used to generate f’s key. By using PPRFs instead of the key trees leveraged by prior work, Holepunch reduces both the memory pressure caused by key management and the number of disk IOs needed to access files. Holepunch stores its master key in secure TPM storage, and uses a novel journaling scheme to provide crash consistency between TPM state and on-disk state.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7381520f-5928-4896-8fef-434b03f3a4cfBuilds on1
Related papers
- Practical Backward-Secure Searchable Encryption from Symmetric Puncturable EncryptionShifeng Sun, Xingliang Yuan, Joseph K. Liu, Ron Steinfeld et al.CCS 2018 · 220 citations
- A Fast Secure Deletion Strategy for High-Density Flash Memory through WOM-v CodesJinhua Cui, Kai Tang, Laurence T. YangDAC 2023 · 5 citations
- HOP: Hardware makes Obfuscation PracticalKartik Nayak, Christopher W. Fletcher, Ling Ren, Nishanth Chandran et al.NDSS 2017 · 54 citations
- BurnBox: Self-Revocable Encryption in a World Of Compelled AccessNirvan Tyagi, Muhammad Haris Mughees, Thomas Ristenpart, Ian MiersUSENIX Security 2018 · 10 citations
- Logging to the Danger Zone: Race Condition Attacks and Defenses on System Audit FrameworksRiccardo Paccagnella, Kevin Liao, Dave Tian, Adam BatesCCS 2020 · 43 citations
