Lawful Device Access without Mass Surveillance Risk: A Technical Design Discussion

Lawful Device Access without Mass Surveillance Risk: A Technical Design Discussion
复制标题

没有大规模监视风险的合法设备访问:技术设计讨论

DOI:
--
复制
发表时间:
2018
期刊:
Conference on Computer and Communications Security
影响因子:
--
通讯作者:
S. Savage
S. Savage
中科院分区:
--
文献类型:
--
作者:
S. Savage

文献摘要

被引文献

相似文献

本文提出了一种面向系统的设计,用于支持对具有系统加密存储的“锁定”设备进行法庭授权的数据访问,同时明确抵制大规模监控用途。我们描述了一种完全专注于密码自我托管(即将用户密码的副本存储到设备上的只写组件中)的设计,因此不需要对底层加密算法进行任何更改。此外,通过将任何合法访问建立在长时间的物理扣押基础上,我们排除了大规模监控的使用情形,同时仍然支持合理的调查需求。而且,通过与设备制造商制定逐设备授权协议,这种设计在提供特殊性(即不存在“主密钥”)的同时,避免了创建新的可信机构或组织。最后,通过对这样一种方法进行具体描述,我们希望鼓励在这个设计空间中进一步从技术层面考虑权衡的可能性和局限性。
This paper proposes a systems-oriented design for supporting court-ordered data access to locked" devices with system-encrypted storage, while explicitly resisting large-scale surveillance use. We describe a design that focuses entirely on passcode self-escrow (i.e., storing a copy of the user passcode into a write-only component on the device) and thus does not require any changes to underlying cryptographic algorithms. Further, by predicating any lawful access on extended-duration physical seizure, we foreclose mass-surveillance use cases while still supporting reasonable investigatory interests. Moreover, by couching per-device authorization protocols with the device manufacturer, this design avoids creating new trusted authorities or organizations while providing particularity (i.e., no "master keys" exist). Finally, by providing a concrete description of one such approach, we hope to encourage further technical consideration of the possibilities and limitations of trade-offs in this design space.