Skip to main content
QUICK REVIEW

[論文レビュー] Bugs in our Pockets: The Risks of Client-Side Scanning

Hal Abelson, Ross Anderson|arXiv (Cornell University)|Oct 14, 2021
Privacy-Preserving Technologies in Data参考文献 29被引用数 13
ひとこと要約

この論文は、暗号化の前にユーザー端末で違法なコンテンツをスキャンするという、提案されている技術であるクライアント側スキャン(CSS)を批判している。この技術は、大量監視を可能にするため、プライバシーとセキュリティを損なうと主張する。CSAMのような違法なコンテンツに限定されるという主張にもかかわらず、CSSはシステム的なリスクを生じさせ、敵対者による乱用を可能にし、デジタルシステムへの信頼を損なう。

ABSTRACT

Our increasing reliance on digital technology for personal, economic, and government affairs has made it essential to secure the communications and devices of private citizens, businesses, and governments. This has led to pervasive use of cryptography across society. Despite its evident advantages, law enforcement and national security agencies have argued that the spread of cryptography has hindered access to evidence and intelligence. Some in industry and government now advocate a new technology to access targeted data: client-side scanning (CSS). Instead of weakening encryption or providing law enforcement with backdoor keys to decrypt communications, CSS would enable on-device analysis of data in the clear. If targeted information were detected, its existence and, potentially, its source, would be revealed to the agencies; otherwise, little or no information would leave the client device. Its proponents claim that CSS is a solution to the encryption versus public safety debate: it offers privacy -- in the sense of unimpeded end-to-end encryption -- and the ability to successfully investigate serious crime. In this report, we argue that CSS neither guarantees efficacious crime prevention nor prevents surveillance. Indeed, the effect is the opposite. CSS by its nature creates serious security and privacy risks for all society while the assistance it can provide for law enforcement is at best problematic. There are multiple ways in which client-side scanning can fail, can be evaded, and can be abused.

研究の動機と目的

  • 暗号化通信への法執行部門のアクセスを解決策として提示するクライアント側スキャン(CSS)のセキュリティおよびプライバシー上のリスクを分析すること。
  • CSSがプライバシーと公共の安全の間でバランスの取れた妥協をもたらすという主張に反論すること。
  • CSSが本質的に大量監視を可能にし、国家および非国家アクターによる乱用に弱いことを示すこと。
  • CSSが、容疑者に限らずすべてのユーザーのセキュリティを損なうように、個人デバイスに恒久的なバックドアを導入するため、すべてのユーザーのセキュリティを脅かすことを主張すること。
  • CSSが逆転不能で侵襲的な性質を有するため、政策的ツールとしての導入に対して、厳密な公的監視と拒否を提唱すること。

提案手法

  • デバイス内スキャン、暗号的検証、ポリシー実行メカニズムを含む、CSSの技術的アーキテクチャを分析すること。
  • 敵対者(国家、犯罪組織、親密なパートナーなど)がクライアントデバイスの脆弱性を悪用する可能性を焦点に、CSSの脅威モデルを評価すること。
  • Appleの2021年の提案やGCHQのAI駆動型監視ビジョンを含む、実世界の事例を検討し、スキャン範囲の拡大を実証すること。
  • 安全な実装の可能性を評価し、幅広い研究にもかかわらず、検証可能で信頼できる設計が確立されていないことを強調すること。
  • キーエスコローや傍受と比較し、CSSが乱用に対する法的・技術的障壁が低く、より容易に拡張可能であることを強調すること。
  • 政策的・経済的分析を用いて、CSSが監視のコストを低下させ、大量データ収集をスケーラブルかつ体系的に行えるようにすることを示すこと。
Figure 1: Scanning operation flows. Left : Server-side scanning. Right : Client-side scanning (the main changes are in orange)
Figure 1: Scanning operation flows. Left : Server-side scanning. Right : Client-side scanning (the main changes are in orange)

実験結果

リサーチクエスチョン

  • RQ1クライアント側スキャンは、大量監視を助長せずに、安全かつ透明に実装可能だろうか?
  • RQ2ユーザー端末にスキャンロジックを導入することで、どのような技術的・システム的脆弱性が生じるだろうか?
  • RQ3プライバシーへの影響と法的監視の観点から、CSSは従来の監視手法とどのように異なるだろうか?
  • RQ4すべてのユーザーのデータを個人デバイス上でスキャンするシステムを導入した場合の長期的影響は何か?
  • RQ5CSSの範囲を違法コンテンツに意味的に限定することは可能だろうか、それとも必然的に拡大の道筋が存在するだろうか?

主な発見

  • クライアント側スキャンは、標的型で令状に基づくアクセスから、すべてのユーザー端末を自動的に大量にスキャンするものに、監視の本質を根本から変える。その結果、プライバシーがスケール的に損なわれる。
  • たとえCSAMのみをスキャン対象とする設計であっても、他のコンテンツ分野への監視拡大の前例を生み出す。
  • この技術は、個人デバイスの攻撃面を拡大し、政府や親密なパートナーを含む敵対的アクターによる悪用のリスクを高める。
  • モバイルオペレーティングシステムの不透明性により、スキャンポリシーが議論の余りの違法コンテンツに限定されていることを検証することは不可能である。
  • CSSはプライバシー保護型の解決策ではなく、遠隔で大規模に個人データにアクセス可能にするため、工業的規模の監視の一種と見なされる。
  • 従来の傍受の経済的・法的コストは、監視を安価で広範にわたるものに変え、乱用に対する重要なチェックを失わせる。
Figure 2: From server-side to client side: New compromise paths and advantage points for adversaries ( \textcolor blue $\longrightarrow$ : compromise paths in server-side scanning; \textcolor red $\longrightarrow$ : compromise paths in CSS; \textcolor red $\ext@arrow 0359$ $\relbar$ → ${\textcolor{w
Figure 2: From server-side to client side: New compromise paths and advantage points for adversaries ( \textcolor blue $\longrightarrow$ : compromise paths in server-side scanning; \textcolor red $\longrightarrow$ : compromise paths in CSS; \textcolor red $\ext@arrow 0359$ $\relbar$ → ${\textcolor{w

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。