The concept of Ephemerizer, proposed by Perlman, is a mechanism for assured data deletion. Ephemerizer provides a useful service that expired data deleted from the persistent storage devices will be unrecoverable, even if later on some of the private keys in the system are compromised. However, no security model has ever been proposed for this primitive and existing protocols have not been studied formally. In practice, a potential shortcoming of existing Ephemerizer protocols is that they are supposed to provide only assured deletion but not assured initial disclosure. In other words, there is no guarantee on when the data will be initially disclosed. In this paper, we formalize the notion of Timed-Ephemerizer which can be regarded as augmented Ephemerizer and can provide both assured initial disclosure and deletion for sensitive data. We propose a new Timed-Ephemerizer protocol and prove its security in the proposed security model.
|Title of host publication||Sixth European Workshop on Public Key Services, Applications and Infrastructures|
|Place of Publication||London|
|Number of pages||21|
|Publication status||Published - 2009|
|Name||Lecture Notes in Computer Science|
Tang, Q. (2009). Timed-Ephemerizer: Make Assured Data Appear and Disappear. In Sixth European Workshop on Public Key Services, Applications and Infrastructures (pp. 195-208). (Lecture Notes in Computer Science; Vol. 6391). London: Springer. https://doi.org/10.1007/978-3-642-16441-5_13