Survivability: Beyond Fault Tolerance and Cryptography

Lidong Zhou · 2004

Survivability of a distributed system is the system’s ability to function as expected despite adverse events such as component failures and malicious attacks. By definition, survivability demands reliability and security—two subjects that have been studied in isolation for a long time. On the one hand, the study on reliability fosters research on fault tolerant distributed systems, which centers around the notion of replication and consensus. Various system models have been proposed to capture different types of failures and timing assumptions. On the other hand, security requirements such as confidentiality, integrity, and authenticity have yielded cryptographic building blocks such as encryption/decryption schemes, one-way hash functions, and digital signatures. A misconception naturally arises that a simple integration of fault tolerance mechanisms (such as replicated state machines [13, 15, 4] and Byzantine quorum systems [14]) and cryptography leads to a survivable distributed system. This is unfortunately not true. System models in fault tolerance traditionally rely on the probability distribution of random faults. Malicious attacks, by exploiting worse-case scenarios, often render such statistical analysis inappropriate, thereby debasing the foundation of existing fault tolerance solutions. Replication, a key element for fault tolerance, dictates a distributed architecture that requires protocols for multiple parties. Although such problems have been studied in cryptography as secure multiparty computation

Read the paper · More papers on PaperTik