(Enter summary)
Abstract: In modern operating systems, cryptographic file systems can protect confidential data from unauthorized access. However, once an authorized process has accessed data from a cryptographic file system, the data can appear as plaintext in the unprotected virtual memory backing store, even after system shutdown. The solution described in this paper uses swap encryption for processes in possession of confidential data. Volatile encryption keys are chosen randomly, and remain valid only for short... (Update)
Cited by: More
Understanding Data Lifetime via Whole System Simulation - Jim Chow Ben (2004)
(Correct)
On the Performance, Feasibility, and Use of Forward-Secure.. - Cronin, Jamin, al. (2003)
(Correct)
USENIX Association - The First International
(Correct)
Active bibliography (related documents): More All
2.2: Encrypting Virtual Memory - Provos (2000)
(Correct)
0.5: Slide Attacks - Biryukov, Wagner
(Correct)
0.2: Implementing Internet Key Exchange (IKE) - Hallqvist, Keromytis
(Correct)
Similar documents based on text: More All
0.5: Improving Host Security with System Call Policies - Provos (2002)
(Correct)
0.4: Defending Against Statistical Steganalysis - Provos (2001)
(Correct)
0.3: SC-CFS: Smartcard Secured Cryptographic File System - Itoi (2001)
(Correct)
Related documents from co-citation: More All
9: A cryptographic file system for UNIX
- Blaze - 1993
6: Cryptfs: A Stackable Vnode Level Encryption File System
- Zadok, Badulescu et al. - 1998
6: Secure Deletion of Data from Magnetic and Solid-State Memory (context) - Gutmann - 1996
BibTeX entry: (Update)
Niels Provos, \Encrypting Virtual Memory," In Proceedings of the 9th USENIX Security Symposium, August 2000. http://citeseer.ist.psu.edu/provos00encrypting.html More
@inproceedings{ provosprovosencrypting,
author = "Niels Provos",
title = "Encrypting Virtual Memory",
url = "citeseer.ist.psu.edu/provos00encrypting.html" }
Citations (may not include all citations):
401
The MD5 Message Digest Algorithm (context) - Rivest - 1992
112
File-System Development with Stackable Layers
- Heidemann, Popek - 1994
95
Virtual Memory Primitives for User Programs
- Appel, Li - 1991
85
Construction of Pseudorandom Generator from any One-Way Func..
- Hastad, Impagliazzo et al. - 1993
85
AES Proposal: Rijndael
- Daemen, Rijmen - 1998
84
A Cryptographic Filesystem for Unix
- Blaze - 1993
48
How to Make Replicated Data Secure
- Herlihy, Tygar - 1988
47
Description of a New VariableLength Key (context) - Schneier - 1993
43
Probabilistic Proofs and Pseudo-randomness (context) - Goldreich - 1999
39
Secure Deletion of Data from Magnetic and Solid-State Memory (context) - Gutmann - 1996
30
Design and Implementation of a Transparent Cryptographic Fil.. (context) - Cattaneo, Persiano - 1997
27
Cryptographic Support for Secure Logs on Untrusted Machines (context) - Schneier, Kelsey - 1998
26
Codes and Cryptography (context) - Die, van Oorschot et al. - 1992
19
Improved Cryptanalysis of Rijndael
- Ferguson, Kelsey et al. - 2000
16
Key Management in an Encrypting File System
- Blaze - 1994
15
The Steganographic File System
- Anderson, Needham et al. - 1998
12
The RC4 Encryption Algorithm (context) - Security - 1992
9
The Compression Cache: Using OnLine Compression to Extend Ph.. (context) - Douglis - 1993
6
Linear Statistical Weakness of Alleged RC4 Keystream Generat.. (context) - Dj - 1997
5
The UVM Virtual Memory System
- Cranor, Parulkar - 1999
4
Cryptography in OpenBSD: An Overview
- de Raadt, Hallqvist et al. - 1999
2
Software Generation of Practially Strong Random Numbers (context) - Gutmann - 1998
2
AES Algorithm Eciency (context) - Gladman
2
erential Cryptanalysis to Ciphertext-Only Attacks (context) - Biryukov, Kushilevitz - 1998
1
Hidden Data Transmission by Controlling Electromagnetic Eman.. (context) - Durak
The graph only includes citing articles where the year of publication is known.
Documents on the same site (http://www.citi.umich.edu/u/provos/cv.html): More
Scalable Network I/O in Linux - Provos, Lever (2000)
(Correct)
Cryptography in OpenBSD: An Overview - de Raadt, Hallqvist, Grabowski.. (1999)
(Correct)
Analyzing the Overload Behavior of a Simple Web Server - Provos, Lever, Tweedie (2000)
(Correct)
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC