Lawful Device Access without Mass Surveillance Risk: A Technical Design Discussion
Stefan Savage
Abstract
This paper proposes a systems-oriented design for supporting courtordered data access to "locked" devices with system-encrypted storage, while explicitly resisting large-scale surveillance use. We describe a design that focuses entirely on passcode self-escrow (i.e., storing a copy of the user passcode into a write-only component on the device) and thus does not require any changes to underlying cryptographic algorithms. Further, by predicating any lawful access on extended-duration physical seizure, we foreclose mass-surveillance use cases while still supporting reasonable investigatory interests. Moreover, by couching per-device authorization protocols with the device manufacturer, this design avoids creating new trusted authorities or organizations while providing particularity (i.e., no "master keys" exist). Finally, by providing a concrete description of one such approach, we hope to encourage further technical consideration of the possibilities and limitations of tradeoffs in this design space.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e662cfe5-85e4-4868-8491-a8d47c16bd84Cited by top-tier papers6
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 50 citations
- Pretty Good Phone PrivacyPaul Schmitt, Barath RaghavanUSENIX Security 2021 · 24 citations
- Abuse Resistant Law Enforcement Access SystemsMatthew Green, Gabriel Kaptchuk, Gijs Van LaerEUROCRYPT 2021 · 17 citations
- Protecting Cryptography Against Compelled Self-IncriminationSarah Scheffler, Mayank VariaUSENIX Security 2021 · 10 citations
- Thwarting Smartphone SMS Attacks at the Radio Interface LayerHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Zhiqiang LinNDSS 2023
Builds on1
Related papers
- BurnBox: Self-Revocable Encryption in a World Of Compelled AccessNirvan Tyagi, Muhammad Haris Mughees, Thomas Ristenpart, Ian MiersUSENIX Security 2018 · 10 citations
- Mitigating Risk while Complying with Data Retention LawsLuis Vargas, Gyan Hazarika, Rachel Culpepper, Kevin R. B. Butler et al.CCS 2018 · 9 citations
- DORY: An Encrypted Search System with Distributed TrustEmma Dauterman, Eric Feng, Ellen Luo, Raluca Ada Popa et al.OSDI 2020 · 77 citations
- Searching Encrypted Data with Size-Locked IndexesMin Xu, Armin Namavari, David Cash, Thomas RistenpartUSENIX Security 2021 · 10 citations
- Practical Accountability of Secret ProcessesJonathan Frankle, Sunoo Park, Daniel Shaar, Shafi Goldwasser et al.USENIX Security 2018 · 63 citations
