Visible to the public Sanitizing Data is Not Enough!: Towards Sanitizing Structural Artifacts in Flash Media

TitleSanitizing Data is Not Enough!: Towards Sanitizing Structural Artifacts in Flash Media
Publication TypeConference Paper
Year of Publication2016
AuthorsChen, Bo, Jia, Shijie, Xia, Luning, Liu, Peng
Conference NameProceedings of the 32Nd Annual Conference on Computer Security Applications
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4771-6
KeywordsCollaboration, data deletion, flash translation layer, Human Behavior, NAND flash, pubcrawl, Scalability, truely secure deletion
Abstract

Conventional overwriting-based and encryption-based secure deletion schemes can only sanitize data. However, the past existence of the deleted data may leave artifacts in the layout at all layers of a computing system. These structural artifacts may be utilized by the adversary to infer sensitive information about the deleted data or even to fully recover them. The conventional secure deletion solutions unfortunately cannot sanitize them. In this work, we introduce truly secure deletion, a novel security notion that is much stronger than the conventional secure deletion. Truly secure deletion requires sanitizing both the obsolete data as well as the corresponding structural artifacts, so that the resulting storage layout after a delete operation is indistinguishable from that the deleted data never appeared. We propose TedFlash, a Truly secure deletion scheme for Flash-based block devices. TedFlash can successfully sanitize both the data and the structural artifacts, while satisfying the design constraints imposed for flash memory. Security analysis and experimental evaluation show that TedFlash can achieve the truly secure deletion guarantee with a small additional overhead compared to conventional secure deletion solutions.

URLhttp://doi.acm.org/10.1145/2991079.2991101
DOI10.1145/2991079.2991101
Citation Keychen_sanitizing_2016