Mitigating Risk while Complying with Data Retention Laws
Luis Vargas, Gyan Hazarika, Rachel Culpepper, Kevin R. B. Butler, Thomas Shrimpton, Doug Szajda, Patrick Traynor
摘要
Data breaches represent a signicant threat to organizations. While the general problem of protecting data has received much attention, one large (and growing) class has not -data that must be kept due to mandatory retention laws. Such data is often of little use to an organization, is rarely accessed, and represents a signicant potential liability, yet cannot be discarded. Protecting such data entails an unusual combination of practical constraints (such as providing verication to a party that may be unknown) and thus requires functionality that is not well addressed by traditional cryptographic primitives. We propose to mitigate the risk to such data through a new system called Dragchute, which creates a time window during which locked data cannot be accessed by anyone. Based on a veriable non-interactive, non-parallelizable, time-delay key escrow mechanism, Dragchute is novel in that it requires that no cryptographic material capable of providing early access to the data be retained, yet provides verication for multiple properties. We dene a base construction for Dragchute, show possible extensions that help meet additional verication requirements, and characterize its performance. Our results show that Dragchute systems oer veriable, customizable, computational protection against data exposure for encryption costs similar to traditional methods (e.g., less than 6% overhead compared to AEAD). We thus show that Dragchute systems provide a critical new means for protecting data that must be retained long term due to mandatory retention laws. CCS CONCEPTS • Security and privacy → Cryptography; Database and storage security;
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper3
- Ligero: Lightweight Sublinear Arguments Without a Trusted SetupScott Ames, Carmit Hazay, Yuval Ishai, Muthuramakrishnan VenkitasubramaniamCCS 2017 · 被引用 338 次
- Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for ServicesMatteo Campanelli, Rosario Gennaro, Steven Goldfeder, Luca NizzardoCCS 2017 · 被引用 170 次
- Egalitarian ComputingAlex Biryukov, Dmitry KhovratovichUSENIX Security 2016 · 被引用 26 次
相关 Paper
- Lawful Device Access without Mass Surveillance Risk: A Technical Design DiscussionStefan SavageCCS 2018 · 被引用 22 次
- Timelock Drive: Isolated Time-Based Defense for Storage SystemsJonah Rosenblum, Juechu Dong, Peter Chen, Satish NarayanasamyOSDI 2026
- HARDLOG: Practical Tamper-Proof System Auditing Using a Novel Audit DeviceAdil Ahmad, Sangho Lee, Marcus PeinadoS&P 2022 · 被引用 46 次
- INVISILINE: Invisible Plausibly-Deniable StorageSandeep Kiran Pinjala, Bogdan Carbunar, Anrin Chakraborti, Radu SionS&P 2024 · 被引用 3 次
- Anamorphic Encryption: Private Communication Against a DictatorGiuseppe Persiano, Duong Hieu Phan, Moti YungEUROCRYPT 2022 · 被引用 45 次
