Publications
Percival: A searchable secret-split datastore
Abstract
Maintaining information privacy is challenging when sharing data across a distributed long-term datastore. In such applications, secret splitting the data across independent sites has been shown to be a superior alternative to fixed-key encryption; it improves reliability, reduces the risk of insider threat, and removes the issues surrounding key management. However, the inherent security of such a datastore normally precludes it from being directly searched without reassembling the data; this, however, is neither computationally feasible nor without risk since reassembly introduces a single point of compromise. As a result, the secret-split data must be pre-indexed in some way in order to facilitate searching. Previously, fixed-key encryption has also been used to securely pre-index the data, but in addition to key management issues, it is not well suited for long term applications. To meet these needs, we have …
- Date
- May 30, 2015
- Authors
- Joel C Frank, Shayna M Frank, Lincoln A Thurlow, Thomas M Kroeger, Ethan L Miller, Darrell DE Long
- Conference
- 2015 31st Symposium on Mass Storage Systems and Technologies (MSST)
- Pages
- 1-12
- Publisher
- IEEE