A study of HSM based key protection in encryption file system
Wenqian Yu, Li Weigang, Junyuan Wang, Changzheng Wei
Abstract
Wenqian Yu, Li Weigang, Junyuan Wang, Changzheng Wei
Abstract
Encryption file system is designed to protect sensitive data stored on storage media. However, file encryption key is normally saved in memory with plaintext in the current known solutions. This brings potential security vulnerability such as the cold boot attack which can steal the file encryption key and in the end the encrypted file can be decrypted by the stolen key. This paper studies the current widely used encryption file systems, and proposes a key protection solution based on the Hardware Security Module (HSM) and our experiment on top of Linux Ext4 file system.
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Encryption file system is designed to protect sensitive data stored on storage media. However, file encryption key is normally saved in memory with plaintext in the current known solutions. This brings potential security vulnerability such as the cold boot attack which can steal the file encryption key and in the end the encrypted file can be decrypted by the stolen key. This paper studies the current widely used encryption file systems, and proposes a key protection solution based on the Hardware Security Module (HSM) and our experiment on top of Linux Ext4 file system.
Key concepts: Computer science, Encryption, On-the-fly encryption, Filesystem-level encryption, File system, Operating system, Self-certifying File System, Key (lock)