PD-DM: An efficient locality-preserving block device mapper with plausible deniability

PD-DM: An efficient locality-preserving block device mapper with plausible deniability
复制标题

PD-DM:一种高效的保留局部性的块设备映射器,具有合理的可否认性

DOI:
--
复制
发表时间:
2019
影响因子:
--
通讯作者:
R. Sion
R. Sion
中科院分区:
--
文献类型:
--
作者:
Chen Chen;Anrin Chakraborti;R. Sion

文献摘要

被引文献

相似文献

抽象的加密保护敏感的数据免受未经授权的访问,但是当用户被迫在胁迫下投降键时,不仅可以使用户加密数据,而且还可以否认它的存在。成功且不幸的是现已灭绝的TrueCrypt)处理“单一快照”对手,无法处理更现实的对手在多个时间点上访问设备的方案。 - 大小的磁盘。确保在这项工作中的合理性。降低了由于随机访问而引起的搜索的影响;在现有工作上按数量级(典型设置中的10–100×)吞吐量,同时保持对多Snapshot对手的强大合理性可否认性,尤其是PD-DM。 (DM-Crypt)用于随机I/O。
Abstract Encryption protects sensitive data from unauthorized access, yet is not sufficient when users are forced to surrender keys under duress. In contrast, plausible deniability enables users to not only encrypt data but also deny its existence when challenged. Most existing plausible deniability work (e.g. the successful and unfortunately now-defunct TrueCrypt) tackles “single snapshot” adversaries, and cannot handle the more realistic scenario of adversaries gaining access to a device at multiple time points. Such “multi-snapshot” adversaries can simply observe modifications between snapshots and detect the existence of hidden data. Existing ideas handling “multi-snapshot” scenarios feature prohibitive overheads when deployed on practically-sized disks. This is mostly due to a lack of data locality inherent in certain standard access-randomization mechanisms, one of the building blocks used to ensure plausible deniability. In this work, we show that such randomization is not necessary for strong plausible deniability. Instead, it can be replaced by a canonical form that permits most of writes to be done sequentially. This has two key advantages: 1) it reduces the impact of seek due to random accesses; 2) it reduces the overall number of physical blocks that need to be written for each logical write. As a result, PD-DM increases I/O throughput by orders of magnitude (10–100× in typical setups) over existing work while maintaining strong plausible deniability against multi-snapshot adversaries. Notably, PD-DM is the first plausible-deniable system getting within reach of the performance of standard encrypted volumes (dm-crypt) for random I/O.