|
|
SECURITY LAB SEMINAR
May 19, 1999
1-2pm
1131 EU II
Ricardo Anguiano discusses Ross Anderson's paper "Eternity
Service Goals"
Outline
A Modest Implementation (Adam Back)
Ian Goldberg and David Wagner (1997). "TAZ Servers and
the Rewebber Network: Enabling Anonymous Publishing on the World Wide
Web" University of California, Berkeley, CS 268 Final Project - May
16, 1997.
-
The Eternity Service
- Abstract
- Proposes the construction of a storage medium resistant to
Denial of Service (DoS).
- Built using redundancy and scattering techniques to replicate
data across a large set of machines
- Add anonymity mechanisms to drive up cost of DoS attacks.
- Historical Background
- Medieval times, knowledge was guarded and controlled.
- Church controlled bible, encoded in Latin.
- Guilds guarded their secrets, restricted competition
- Gutenberg allows quick dissemination of information with
the advent of the printing press.
- Control of information leads to less competitive and a less
successful society.
- Electron publishing threatens greater control over publishing.
- Today
- Information is now easier to control.
- Church of scientology, former members published secret material,
court ordered material removed from US server. Mirror server
in Amsterdam à an anonymous
remailer in Finland
- So publishing means putting electronic copies on some servers
worldwide, which can be removed.
- Documents can be de-published.
- Can we assure the availability of the data against bugs,
spy agencies, military, judges and courts?
- Preventing Denial of Service
- DoS is the neglected stepchild of computer security, yet
is the most important outside of military, diplomatic communities
(figures from budgets)
- Lots of motivation for prevention of destruction of records
- Birth/death records
- Pollution registries
- Medical Case Notes
- Financial accounting
- Audit Trails
- Certificate Revocation Lists
- Digital document longevity beyond the life of the media.
- All these examples motivate a highly persistent file store.
- Previous Work
- Disaster recovery companies
- Companies not Prepared
- Availability linked to anonymity?
- Anonymous signaling prevent selective denial of service
- If physical location of www site can't be ascertained, no
seizure order can be saved.
- How to realize anonymous publication.
- Eternity Service Goals
- Example: Want to store 1 MB file for 50 years. Publisher
uploads "digital counter" file, no proof of identity required.
Once published, available by anonymous file transfer.
- Copies stored on servers around the world. All are independent.
- Diversity provides resilience against attacks and errors.
- Once posted, cannot be deleted
- Resistant to destruction of most participating file servers,
and malicious conspiracy of attacks by most servers
- Servers dispersed in many jurisdictions.
- Threat model
- World wide government base unlikely.
- Local base likely, would not affect service in other areas
- Net flood, provide many access points
- Basic idea explores redundancy versus anonymity.
- Simple Design
- 100 servers. Each server remembers a random set of 10 of
them to audit, enforce contract
- Broadcast message, servers send copy via anonymous remailer.
- Perjury Trap
- Can't delete without security officer
- Login banner requires that the officer declare under oath
that he is a free agent. Only authorized under condition of
free will.
- Courts in most countries will not compel people to commit
perjury.
- Proof Hardware
- Hardware alone is not enough. Hardware + protocol maybe.
- Security Server
- File uploaded, security server will share with other security
servers, in other jurisdictions, which in turn send copies
to other security servers in other jurisdictions.
- Anonymized communication to prevent traffic analysis (mix
nets, ring, padding)
- Indexing
- Index is a file on a system.
- Aim is for seamless integration within intranet.
- Payment
- "Digital Cash" generates an "electronic annuity" which follows
data around.
- Economics for file server owners
- Disk costs decrease fast
- Annuity pay is the same over time
- Requires a double blind system for confidentiality
- Bank backs annuity
- Problems - Not yet handled by digital cash research
- Audit? Accounting? Prevent money laundering
- Threat: Delay payment until file is flushed
- Opponent bugs servers, enough so they have all the copies.
- ISP gets big, penetrates anonymity of communications.
- Certify owners?
- Central body bad idea
- Distributed certification of owners can't investigate owners
- Policy up to the publisher
- Cheating File Server Owner
- Collect annuity, without keeping file, download from Eternity
Server to show copy. Annuity payment server sends challenge.
- Time
- Opponent may manipulate NTP à
now 2500 AD delete files
- No secure clock
- Policy rules
- Assets may not be deleted unless date confirmed, all payments
received ¾
-
Questions/Comments
- TA: It's easier to destroy data of a document published on
the Internet.
- CW: Scientific papers can be republished weekly.
- CW: There is no secure notary time service available on the
Internet.
- CW: Integrity over time versus over space. 100% integrity is
not essential - you don't need all the data
- TA: When everyone is anonymous, it makes it difficult for the
server to pick out one user - treats everyone the same.
- TA: The Internet is an anarchy system - it can't be organized.
So you can't reliably store or destroy data. In the anarchy systems
is organized, you become dependent on local service.
- CW: The public switch telephone network is used for both criminal
and legitimate activity. The local jurisdiction may not want to
shut down a server because of some criminal activity, because
the benefit and legitimate activity outweighs the bad.
- KL: Pay for protection services instead of publishing services
- CW: Insurance companies determine risk management all the time.
- KL: Pay for reliable clock service as part of the package.
- KL: Any papers on market models?
- NP: Student workshop paper.
|