Secure logging of retained data for an anonymity service

Publikation: Beitrag in Buch/Konferenzbericht/Sammelband/GutachtenBeitrag in KonferenzbandBeigetragenBegutachtung

Beitragende

Abstract

The recently introduced legislation on data retention to aid prosecuting cyber-related crime in Europe also affects the achievable security of systems for anonymous communication on the Internet. We have analyzed the newly arising risks associated with the process of accessing and storage of the retained data and propose a secure logging system, which utilizes cryptographic smart cards, trusted time stamping servers and distributed storage. These key components will allow for controlled access to the stored log data, enforce a limited data retention period, ensure integrity of the logged data, and enable reasonably convenient response to any legitimated request of the retained data. A practical implementation of the proposed scheme was performed for the AN.ON anonymity service, but the scheme can be used for other services affected by data retention legislation.

Details

OriginalspracheEnglisch
TitelPrivacy and Identity Management for Life - 5th IFIP WG 9.2, 9.6/11.7, 11.4, 11.6/PrimeLife International Summer School, 2009, Revised Selected Papers
Redakteure/-innenMichele Bezzi, Penny Duquenoy, Simone Fischer-Hubner, Ge Zhang, Marit Hansen
Herausgeber (Verlag)Springer Verlag, New York
Seiten284-298
Seitenumfang15
ISBN (Print)9783642142819
PublikationsstatusVeröffentlicht - 2010
Peer-Review-StatusJa

Publikationsreihe

ReiheIFIP Advances in Information and Communication Technology
Band320
ISSN1868-4238

Konferenz

Titel5th IFIP WG 9.2, 9.6/11.7, 11.4, 11.6/PrimeLife International Summer School, 2009
Dauer7 - 11 September 2009
StadtNice
LandFrankreich

Externe IDs

ORCID /0000-0002-0466-562X/work/142246158