An Assured Deletion Technique for Cloud-Based IoT
Bryan Hall, Manimaran Govindarasu · 2018
The Internet of Things (IoT) and the cloud are expanding technologies with many security vulnerabilities. With at least one major data leak every year since 2004, the public's concern for data privacy has given rise to legislation known as the General Data Protection Regulation (GDPR) in the European Union. Assured deletion, the process by which deleted data on the cloud is made permanently unrecoverable, is a strong defense against data leaks. The existing assured deletion techniques fall into two categories: cryptographic protection and secure overwriting. Cryptographic protection blocks malicious preservation of data but leaves the data subject to cryptanalysis. Secure overwriting prevents cryptanalysis attacks but leaves the data subject to malicious preservation of data. Furthermore, both cryptographic protection and secure overwriting are too expensive for direct application to IoT technology. To address these problems, we proposed a hybrid assured deletion technique which combines cryptographic protection with secure overwriting on a semi- trusted cloud host. By moving the computation operations of assured deletion from the IoT device to a semi-trusted cloud host, we reduce the latency of the operations while relieving the IoT device of the processing overhead. By combining cryptographic protection with secure overwriting, the outsourced data is safeguarded from both vulnerabilities. We evaluated the proposed technique for latency performance and attack exposure. The results show that the latency performance of the hybrid technique was comparable to that of the cryptographic protection, and its overall attack surface is better than both the cryptographic protection and secure overwrite solutions.