Self-Expiring Data Capsule using Trusted Execution Environment

11/21/2019
by   Hung Dang, et al.
0

Data privacy is unarguably of extreme importance. Nonetheless, there exist various daunting challenges to safe-guarding data privacy. These challenges stem from the fact that data owners have little control over their data once it has transgressed their local storage and been managed by third parties whose trustworthiness is questionable at times. Our work seeks to enhance data privacy by constructing a self-expiring data capsule. Sensitive data is encapsulated into a capsule which is associated with an access policy an expiring condition. The former indicates eligibility of functions that can access the data, and the latter dictates when the data should become inaccessible to anyone, including the previously eligible functions. Access to the data capsule, as well as its dismantling once the expiring condition is met, are governed by a committee of independent and mutually distrusting nodes. The pivotal contribution of our work is an integration of hardware primitive, state machine replication and threshold secret sharing in the design of the self-expiring data encapsulation framework. We implement the proposed framework in a system called TEEKAP. Our empirical experiments conducted on a realistic deployment setting with the access control committee spanning across four geographical regions reveal that TEEKAP can process access requests at scale with sub-second latency.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/01/2010

A Data Capsule Framework For Web Services: Providing Flexible Data Access Control To Users

This paper introduces the notion of a secure data capsule, which refers ...
research
02/16/2022

Data Capsule: A Self-Contained Data Model as an Access Policy Enforcement Strategy

In this paper, we introduce a data capsule model, a self-contained and s...
research
01/15/2022

SS-3DCapsNet: Self-supervised 3D Capsule Networks for Medical Segmentation on Less Labeled Data

Capsule network is a recent new deep network architecture that has been ...
research
08/30/2019

Data Capsule: A New Paradigm for Automatic Compliance with Data Privacy Regulations

The increasing pace of data collection has led to increasing awareness o...
research
10/13/2021

3LSAA: A Secure And Privacy-preserving Zero-knowledge-based Data-sharing Approach Under An Untrusted Environment

As data collection and analysis become critical functions for many cloud...
research
10/16/2019

Consentio: Managing Consent to Data Access using Permissioned Blockchains

The increasing amount of personal data is raising serious issues in the ...
research
07/10/2018

Medical Technologies and Challenges of Robot Assisted Minimally Invasive Intervention and Diagnostics

Emerging paradigms furthering the reach of medical technology deeper int...

Please sign up or login with your details

Forgot password? Click here to reset