Crypto Crumple Zones: Enabling Limited Access without Mass Surveillance

Crypto Crumple Zones: Enabling Limited Access without Mass Surveillance
复制标题

加密溃缩区:在没有大规模监控的情况下实现有限访问

DOI:
--
复制
发表时间:
2018
期刊:
European Symposium on Security and Privacy
影响因子:
--
通讯作者:
Mayank Varia
Mayank Varia
中科院分区:
--
文献类型:
--
作者:
C. V. Wright;Mayank Varia

文献摘要

被引文献

相似文献

世界各国政府都要求更多地获取加密数据,但一直难以建立一个既能让当局在一定程度上获取数据,又不会在实际操作中提供无限制访问权限的系统。在本文中,我们提出了一些新技术,用于在要求支持对加密数据进行所谓“特殊访问”的司法管辖区内最大限度地保护用户隐私。与之前关于该主题的研究(例如密钥托管)不同,我们的方法将实现特殊访问的大部分责任置于政府身上,而不是加密工具的用户或开发者。因此,我们的构建非常简单且轻量化,可以很容易地对现有应用程序和协议进行改造。关键的是,我们没有引入新的第三方,并且在已经使用迪菲 - 赫尔曼(Diffie - Hellman)的协议中,除了一个新的迪菲 - 赫尔曼密钥交换外,没有增加新的消息。我们提出了两种构建方法,使得政府有可能(尽管成本极高)恢复目标消息的明文。首先,我们的对称压缩技术使用基于哈希的工作量证明,对攻击者想要恢复的每条消息施加线性成本。其次,我们的公钥磨损方法在模算术群上使用迪菲 - 赫尔曼的一种新应用,创建了一个极其复杂的难题,攻击者在恢复哪怕一条消息之前都必须解决这个难题。我们的初步分析表明,我们可以设定前期成本在1亿美元到数十亿美元之间,每条消息的线性成本在1000美元到100万美元之间。我们展示了我们的构建如何能够轻松地适用于常见工具,包括PGP、Signal、SRTP、全盘加密和基于文件的加密。
Governments around the world are demanding more access to encrypted data, but it has been difficult to build a system that allows the authorities some access without providing unlimited access in practice. In this paper, we present new techniques for maximizing user privacy in jurisdictions that require support for so-called "exceptional access" to encrypted data. In contrast to previous work on this topic (e.g., key escrow), our approach places most of the responsibility for achieving exceptional access on the government, rather than on the users or developers of cryptographic tools. As a result, our constructions are very simple and lightweight, and they can be easily retrofitted onto existing applications and protocols. Critically, we introduce no new third parties, and we add no new messages beyond a single new Diffie-Hellman key exchange in protocols that already use Diffie-Hellman. We present two constructions that make it possible— although arbitrarily expensive—for a government to recover the plaintext for targeted messages. First, our symmetric crumpling technique uses a hash-based proof of work to impose a linear cost on the adversary for each message she wishes to recover. Second, our public key abrasion method uses a novel application of Diffie-Hellman over modular arithmetic groups to create an extremely expensive puzzle that the adversary must solve before she can recover even a single message. Our initial analysis shows that we can impose an upfront cost in the range of $100M to several billion dollars and a linear cost between $1K-$1M per message. We show how our constructions can easily be adapted to common tools including PGP, Signal, SRTP, full-disk encryption, and file-based encryption.