A Proof of Secure Erasure (PoSE) is a communication protocol where a verifier seeks evidence that a prover has erased its memory within the time frame of the protocol execution. Designers of PoSE protocols have long been aware that, if a prover can outsource the computation of the memory erasure proof to another device, then their protocols are trivially defeated. As a result, most software-based PoSE protocols in the literature assume that provers are isolated during the protocol execution, that is, provers cannot receive help from a network adversary. Our main contribution is to show that this assumption is not necessary. We introduce formal models for PoSE protocols playing against provers aided by external conspirators and develop three PoSE protocols that we prove secure in this context. We reduce the requirement of isolation to the more realistic requirement that the communication with the external conspirator is relatively slow. Software-based protocols with such relaxed isolation assumptions are especially pertinent for low-end devices, where it is too costly to deploy sophisticated protection methods.
翻译:安全擦除证明(PoSE)是一种通信协议,其中验证方寻求证据,证明证明方已在协议执行的时间范围内擦除了其内存。PoSE协议的设计者长期以来一直意识到,如果证明方能够将内存擦除证明的计算外包给另一台设备,那么他们的协议就会被轻易击败。因此,文献中大多数基于软件的PoSE协议都假设证明方在协议执行期间处于隔离状态,即证明方无法从网络对手处获得帮助。我们的主要贡献在于表明这一假设并非必要。我们引入了针对受外部共谋者协助的证明方的PoSE协议形式化模型,并开发了三种在此情境下被证明安全的PoSE协议。我们将隔离要求降低为更现实的要求,即与外部共谋者的通信相对较慢。这种具有放松隔离假设的基于软件协议尤其适用于低成本设备,在这些设备中部署复杂的保护方法成本过高。