Preserving Hidden Data with an Ever-Changing Disk

Preserving Hidden Data with an Ever-Changing Disk
复制标题

使用不断变化的磁盘保留隐藏数据

DOI:
--
复制
发表时间:
2017
期刊:
USENIX Workshop on Hot Topics in Operating Systems
影响因子:
--
通讯作者:
Dan Tsafrir
Dan Tsafrir
中科院分区:
--
文献类型:
--
作者:
A. Zuck;Udi Shriki;Donald E. Porter;Dan Tsafrir

文献摘要

被引文献

相似文献

本文提出了一个存储系统,该系统可以将隐藏数据的存在与大量公共数据一起隐藏。加密允许用户隐藏数据的内容,但不能隐藏存在敏感数据的事实。在胁迫下,高价值数据的所有者可以由强大的对手强制披露解密密钥。因此,私人用户和公司有兴趣隐藏一些敏感数据的存在,以及较大的敏感数据(例如,操作系统和其他良性文件)的较大机构;该属性称为合理的可否认性。现有合理的可否认系统不能满足以下所有要求:(1)攻击者随着时间的推移比较设备状态的多个快照攻击的阻力; (2)确保当用户不了解隐藏数据来修改公共卷时不会破坏隐藏的数据; (3)伪装将秘密数据作为公共数据正常操作的秘密数据。我们解释了为什么现有解决方案不符合所有这些要求,并呈现不断变化的磁盘(ECD),这是满足所有这些要求的合理可否认存储系统的通用计划。 ECD将隐藏的数据存储在大量伪随机数据中。该卷的部分以日志结构方式定期迁移。然后,隐藏的写入可以与普通固件操作互换。覆盖隐藏数据的预期访问模式和时间是完全可以预测的,并且对数据是否隐藏不敏感。用户控制内部数据迁移(R)的速率,交易将带宽与隐藏数据的隐藏数据延长。对于典型的2TB磁盘和R的设置,用户每隔几天或几周输入她的秘密密钥来保留隐藏的数据。
This paper presents a storage system that can hide the presence of hidden data alongside a larger volume of public data. Encryption allows a user to hide the contents of data, but not the fact that sensitive data is present. Under duress, the owner of high-value data can be coerced by a powerful adversary to disclose decryption keys. Thus, private users and corporations have an interest in hiding the very presence of some sensitive data, alongside a larger body of less sensitive data (e.g., the operating system and other benign files); this property is called plausible deniability. Existing plausible deniability systems do not fulfill all of the following requirements: (1) resistance to multiple snapshot attacks where an attacker compares the state of the device over time; (2) ensuring that hidden data won't be destroyed when the public volume is modified by a user unaware of the hidden data; and (3) disguising writes to secret data as normal system operations on public data. We explain why existing solutions do not meet all these requirements and present the Ever-Changing Disk (ECD), a generic scheme for plausible deniability storage systems that meets all of these requirements. An ECD stores hidden data inside a large volume of pseudorandom data. Portions of this volume are periodically migrated in a log-structured manner. Hidden writes can then be interchanged with normal firmware operations. The expected access patterns and time until hidden data is overwritten are completely predictable, and insensitive to whether data is hidden. Users control the rate of internal data migration (R), trading write bandwidth to hidden data for longevity of the hidden data. For a typical 2TB disk and setting of R, a user preserves hidden data by entering her secret key every few days or weeks.