Skip to main content
QUICK REVIEW

[论文解读] Unbreakable distributed storage with quantum key distribution network and password-authenticated secret sharing

Mikio Fujiwara, Atsushi Waseda|arXiv (Cornell University)|Jul 2, 2016
Quantum Computing Algorithms and Architecture被引用 5
一句话总结

本文提出了一种不可破解的分布式存储系统,结合量子密钥分发(QKD)实现安全密钥交换,以及基于密码的认证秘密共享(PASS)实现用户友好的认证。通过将基于QKD的安全信道与单密码保护的秘密共享方案相结合,该系统在抵御窃听和蛮力攻击方面实现了信息论安全性,已在东京都市网络中完成真实部署。

ABSTRACT

Distributed storage plays an essential role in realizing robust and secure data storage in a network over long periods of time. A distributed storage system consists of a data owner machine, multiple storage servers and channels to link them. In such a system, secret sharing scheme is widely adopted, in which secret data are split into multiple pieces and stored in each server. To reconstruct them, the data owner should gather plural pieces. Shamir's (k, n)-threshold scheme, in which the data are split into n pieces (shares) for storage and at least k pieces of them must be gathered for reconstruction, furnishes information theoretic security, that is, even if attackers could collect shares of less than the threshold k, they cannot get any information about the data, even with unlimited computing power. Behind this scenario, however, assumed is that data transmission and authentication must be perfectly secure, which is not trivial in practice. Here we propose a totally information theoretically secure distributed storage system based on a user-friendly single-password-authenticated secret sharing scheme and secure transmission using quantum key distribution, and demonstrate it in the Tokyo metropolitan area.

研究动机与目标

  • 解决在传统通信和认证假设无法完全成立的实际场景中,实现分布式存储系统信息论安全性的挑战。
  • 通过用量子密钥分发替代经典加密来实现安全密钥交换,消除对计算困难性假设的依赖。
  • 通过PASS协议实现使用单个密码的用户友好型数据访问,同时保持信息论安全性。
  • 在真实都市规模的量子网络中,验证所提出系统的可行性和鲁棒性。

提出的方法

  • 系统采用(k, n)-门限秘密共享方案,将数据分割为n个数据分片,分别存储于n个服务器上,至少需要k个分片才能重建原始数据。
  • 采用量子密钥分发(QKD)在数据拥有者与每个存储服务器之间生成并分发一次性密码本密钥,确保信息论安全的通信。
  • 使用基于密码的认证秘密共享(PASS)协议,通过单个用户密码对数据拥有者与服务器进行认证,防止蛮力攻击。
  • 系统将QKD保护的信道与PASS协议结合,保护密钥交换与数据传输,确保端到端安全。
  • 已实现原型系统并在东京都市区域进行测试,利用现有QKD基础设施验证性能与安全性。

实验结果

研究问题

  • RQ1在不依赖计算假设的前提下,分布式存储系统能否实现信息论安全性?
  • RQ2在需要强安全保证的系统中,如何实现用户友好的认证机制?
  • RQ3在真实都市规模网络中,部署基于QKD保护、集成PASS协议的分布式存储系统是否可行?
  • RQ4在实际环境中,结合QKD与PASS的性能与安全性权衡如何?

主要发现

  • 所提出的系统在数据传输与认证方面均实现了信息论安全性,即使在无限计算能力下也无法被破解。
  • QKD与PASS的集成实现了安全的基于密码的访问机制,同时确保密码不会被窃听者获取或遭受蛮力破解。
  • 该系统已在东京都市区域的真实部署中成功验证,证明了其实际可行性。
  • 使用单个密码进行认证显著提升了易用性,相较于传统多因素或基于密钥的系统,安全性未受影响。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。