Secure Logging of Retained Data for an Anonymity Service - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

Secure Logging of Retained Data for an Anonymity Service

Résumé

The recently introduced legislation on data retention to aid prosecuting cyber-related crime in Europe also affects the achievable security of systems for anonymous communication on the Internet. We have analyzed the newly arising risks associated with the process of accessing and storage of the retained data and propose a secure logging system, which utilizes cryptographic smart cards, trusted timestamping servers and distributed storage. These key components will allow for controlled access to the stored log data, enforce a limited data retention period, ensure integrity of the logged data, and enable reasonably convenient response to any legitimated request of the retained data. A practical implementation of the proposed scheme was performed for the AN.ON anonymity service, but the scheme can be used for other services affected by data retention legislation.
Fichier principal
Vignette du fichier
petr.pdf (330.62 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01061062 , version 1 (05-09-2014)

Licence

Paternité

Identifiants

Citer

Stefan Köpsell, Petr Švenda. Secure Logging of Retained Data for an Anonymity Service. 5th IFIP WG 9.2, 9.6/11.4, 11.6, 11.7/PrimeLife International Summer School(PRIMELIFE), Sep 2009, Nice, France. pp.284-298, ⟨10.1007/978-3-642-14282-6_24⟩. ⟨hal-01061062⟩
115 Consultations
109 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More