skip to main content
10.1145/3176258.3176327acmconferencesArticle/Chapter ViewAbstractPublication PagescodaspyConference Proceedingsconference-collections
research-article

Forgetting with Puzzles: Using Cryptographic Puzzles to support Digital Forgetting

Published: 13 March 2018 Publication History

Abstract

Digital forgetting deals with the unavailability of content uploaded to web and storage servers after the data has served its purpose. The content on the servers can be deleted manually, but this does not prevent data archival and access at different storage locations. This is problematic since then the data may be accessed for unintended or even malicious purposes long after the owners have decided to abandon the public availability of their data. Approaches which assign a lifetime value to data or use heuristics like interest in data to make it inaccessible after some time have been proposed, but digital forgetting is still in its infancy and there are a number of open problems with the proposed approaches.
In this paper, we outline a general use case of cryptographic puzzles in the context of digital forgetting which---to the best of our knowledge---has not been proposed or explored before. One problem with recent proposals for digital forgetting is that attackers could collect or even delete anyone's public data during their lifetime. In our approach, we deal with these problems by making it hard for the attacker to delete large quantities of data while making sure that the proposed solutions will not adversely deteriorate user experience in a disturbing manner. As a proof-of-concept, we propose a system with cryptographic (time-lock) puzzles that deals with malicious users while ensuring the permanent deletion of data when interest in it dies down. We have implemented a prototype and evaluate it thoroughly with promising results.

References

[1]
Adam Back. 2002. Hashcash -- A Denial of Service Counter-Measure. (2002). http://www.hashcash.org/papers/hashcash.pdf
[2]
Dan Boneh and Richard J. Lipton. {n. d.}. A Revocable Backup System. In Proceedings of the 6th USENIX Security Symposium, San Jose, CA, USA, July 22--25, 1996.
[3]
C. Castelluccia, E. De Cristofaro, A. Francillon, and M.-A. Kaafar. 2011. EphPub: Toward robust Ephemeral Publishing. In 19th IEEE International Conference on Network Protocols (ICNP). 165--175.
[4]
Domo. 2017. Data never sleeps 5.0. https://www.domo.com/learn/data-never-sleeps-5. (June. 2017). https://www.domo.com/learn/data-never-sleeps-5
[5]
Sujata Doshi, Fabian Monrose, and Aviel D. Rubin. 2006. Efficient Memory Bound Puzzles Using Pattern Databases Proceedings of the 4th International Conference on Applied Cryptography and Network Security (ACNS). 98--113.
[6]
Roxana Geambasu, Tadayoshi Kohno, Arvind Krishnamurthy, Amit Levy, Henry Levy, Paul Gardner, and Vinnie Moscaritolo. 2011. New Directions for Self-Destructing Data Systems. Technical Report UW-CSE-11-08-01. University of Washington.
[7]
Roxana Geambasu, Tadayoshi Kohno, Amit A. Levy, and Henry M. Levy. 2009. Vanish: Increasing Data Privacy with Self-destructing Data Proceedings of the 18th Conference on USENIX Security Symposium. USENIX Association, Berkeley, CA, USA, 299--316.
[8]
Peter Gutmann. 1996. Secure deletion of data from magnetic and solid-state memory Proceedings of the 6th USENIX Security Symposium, Focusing on Applications of Cryptography. USENIX Association, Berkeley, CA, USA, 77--90.
[9]
Owen Harrison and John Waldron. 2009. Efficient Acceleration of Asymmetric Cryptography on Graphics Hardware Proceedings of the 2Nd International Conference on Cryptology in Africa: Progress in Cryptology (AFRICACRYPT '09). Springer-Verlag, Berlin, Heidelberg, 350--367.
[10]
Ari Juels and John G. Brainard. 1999. Client Puzzles: A Cryptographic Countermeasure Against Connection Depletion Attacks Proceedings of the Network and Distributed System Security Symposium, NDSS.
[11]
Ghassan Karame and Srdjan Capkun. 2010. Low-Cost Client Puzzles Based on Modular Exponentiation Proceedings of the 15th European Symposium on Research in Computer Security (ESORICS). 679--697.
[12]
Jaeheung Lee, Sangho Yi, Junyoung Heo, Hyungbae Park, Sung Y. Shin, and Yookun Cho. 2010. An Efficient Secure Deletion Scheme for Flash File Systems. Journal of Information Science and Engineering, Vol. 26, 1 (2010), 27--38. http://www.iis.sinica.edu.tw/page/jise/2010/201001_03.html
[13]
Frank Li, Prateek Mittal, Matthew Caesar, and Nikita Borisov. 2012. SybilControl: Practical Sybil Defense with Computational Puzzles Proceedings of the Seventh ACM Workshop on Scalable Trusted Computing (STC'12). 67--78.
[14]
Pär Persson Mattsson. 2013. Why Haven't CPU Clock Speeds Increased in the Last Few Years? (Nov. 2013). https://www.comsol.com/blogs/havent-cpu-clock-speeds-increased-last-years/
[15]
Viktor Mayer-Schönberger. 2011. Delete: The Virtue of Forgetting in the Digital Age. Princeton University Press, Princeton, NJ, USA.
[16]
Mainack Mondal, Johnnatan Messias, Saptarshi Ghosh, Krishna P. Gummadi, and Aniket Kate. 2016. Forgetting in Social Media: Understanding and Controlling Longitudinal Exposure of Socially Shared Data. In Twelfth Symposium on Usable Privacy and Security, SOUPS 2016, Denver, CO, USA, June 22-24, 2016. 287--299.
[17]
Joel Reardon, David A. Basin, and Srdjan Capkun. 2013. SoK: Secure Data Deletion. In IEEE Symposium on Security and Privacy (SP), Berkeley, CA, USA. 301--315.
[18]
Joel Reardon, Srdjan Capkun, and David A. Basin. 2012. Data Node Encrypted File System: Efficient Secure Deletion for Flash Memory Proceedings of the 21th USENIX Security Symposium. 333--348.
[19]
Sirke Reimann and Markus Dürmuth. 2012. Timed revocation of user data: long expiration times from existing infrastructure WPES. 65--74.
[20]
Ronald. L. Rivest, Adi Shamir, and David A. Wagner. 1996. Time-lock Puzzles and Timed-release Crypto. Technical Report. Cambridge, MA, USA.
[21]
Esther Shein. 2013. Ephemeral Data. Commun. ACM Vol. 56, 9 (Sept. . 2013), 20--22.

Cited By

View all
  • (2023)Digital Forgetting Using Key DecayProceedings of the 38th ACM/SIGAPP Symposium on Applied Computing10.1145/3555776.3577641(34-41)Online publication date: 27-Mar-2023
  • (2021)Non-Interactive VDF Client Puzzle for DoS MitigationProceedings of the 2021 European Interdisciplinary Cybersecurity Conference10.1145/3487405.3487406(32-38)Online publication date: 10-Nov-2021
  • (2020)SoK: Managing Longitudinal Privacy of Publicly Shared Personal Online DataProceedings on Privacy Enhancing Technologies10.2478/popets-2021-00132021:1(229-249)Online publication date: 9-Nov-2020
  • Show More Cited By

Index Terms

  1. Forgetting with Puzzles: Using Cryptographic Puzzles to support Digital Forgetting

      Recommendations

      Comments

      Information & Contributors

      Information

      Published In

      cover image ACM Conferences
      CODASPY '18: Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy
      March 2018
      401 pages
      ISBN:9781450356329
      DOI:10.1145/3176258
      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

      Sponsors

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      Published: 13 March 2018

      Permissions

      Request permissions for this article.

      Check for updates

      Author Tags

      1. cryptographic puzzles
      2. digital forgetting
      3. time-lock puzzles

      Qualifiers

      • Research-article

      Funding Sources

      • BMBF

      Conference

      CODASPY '18
      Sponsor:

      Acceptance Rates

      CODASPY '18 Paper Acceptance Rate 23 of 110 submissions, 21%;
      Overall Acceptance Rate 149 of 789 submissions, 19%

      Contributors

      Other Metrics

      Bibliometrics & Citations

      Bibliometrics

      Article Metrics

      • Downloads (Last 12 months)17
      • Downloads (Last 6 weeks)3
      Reflects downloads up to 07 Jan 2025

      Other Metrics

      Citations

      Cited By

      View all
      • (2023)Digital Forgetting Using Key DecayProceedings of the 38th ACM/SIGAPP Symposium on Applied Computing10.1145/3555776.3577641(34-41)Online publication date: 27-Mar-2023
      • (2021)Non-Interactive VDF Client Puzzle for DoS MitigationProceedings of the 2021 European Interdisciplinary Cybersecurity Conference10.1145/3487405.3487406(32-38)Online publication date: 10-Nov-2021
      • (2020)SoK: Managing Longitudinal Privacy of Publicly Shared Personal Online DataProceedings on Privacy Enhancing Technologies10.2478/popets-2021-00132021:1(229-249)Online publication date: 9-Nov-2020
      • (2020)Foundations, Properties, and Security Applications of PuzzlesACM Computing Surveys10.1145/339637453:4(1-38)Online publication date: 20-Aug-2020
      • (2020)Rogue people: on adversarial crowdsourcing in the context of cyber securityJournal of Information, Communication and Ethics in Society10.1108/JICES-08-2019-010019:1(87-103)Online publication date: 23-Jul-2020
      • (2019)Towards Contractual Agreements for Revocation of Online DataICT Systems Security and Privacy Protection10.1007/978-3-030-22312-0_26(374-387)Online publication date: 5-Jun-2019

      View Options

      Login options

      View options

      PDF

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader

      Media

      Figures

      Other

      Tables

      Share

      Share

      Share this Publication link

      Share on social media