I can't trust you, but I can believe you

September 10, 2001

However good the security, any computer connected to the Internet is potentially open to attack. Premkumar Devanbu, Michael Gertz, Charles Martell and Phil Rogaway at the University of California, Davis, Computer Security Laboratory have come up with a system that lets exposed, "untrusted" machines go on providing useful, accurate information, even though they might have been infiltrated by hackers.

If you have a database of information, such as a customer database, the only way to be sure that no one breaks into the computer and changes entries is to have that machine locked in a vault with no connection to other computers, Devanbu said. But that means you can't access the data easily.

What you can do is put a copy of the database on an untrusted computer connected to the Internet, along with a digital signature from the "trusted" computer. Users of the database also get copies of the signature. When a user sends a query over the Internet to the database, it sends back the answer, plus a "proof" that guarantees that the answer has come from the correct database. Together, the answer and the proof should give a signature that can be compared to the original. If the database on the open computer has been tampered with, the proof will automatically be wrong.

The proof is derived from the database in such a way that it increases in size by one bit (a one or a zero) when the database doubles in size. Although the proof and the signature are both short, the number of possible combinations they can generate is enormous, making it very hard to forge a proof or signature that could be used to falsify data entries, Devanbu.

This system has important implications, Devanbu said. Essentially, anyone with a computer connected to the Internet could provide database services, as long as they had copies of the original database and signature. For example, stock market prices are provided by brandname Web sites such as Reuter's and Bloomberg. These companies go to great lengths to keep that data secure, and charge accordingly. But if security were not a problem, many more sites could host this publicly available information.

The project is funded by the National Science Foundation. Devanbu's laboratory is also studying ways to extend the signature standard for XML documents, to make it easier to query large documents and verify the answers with a single signature.
-end-
Media contacts:
-- Prem Devanbu, Computer Science, 530-752-7324, devanbu@ucdavis.edu


University of California - Davis

Related Computer Articles from Brightsurf:

UCLA computer scientists set benchmarks to optimize quantum computer performance
Two UCLA computer scientists have shown that existing compilers, which tell quantum computers how to use their circuits to execute quantum programs, inhibit the computers' ability to achieve optimal performance.

Digitize your dog into a computer game
Researchers from CAMERA at the University of Bath have developed motion capture technology that enables you to digitise your dog without a motion capture suit and using only one camera.

Stabilizing brain-computer interfaces
Researchers from Carnegie Mellon University (CMU) and the University of Pittsburgh (Pitt) have published research in Nature Biomedical Engineering that will drastically improve brain-computer interfaces and their ability to remain stabilized during use, greatly reducing or potentially eliminating the need to recalibrate these devices during or between experiments.

Computer-generated genomes
Professor Beat Christen, ETH Zurich to speak in the AAAS 2020 session, 'Synthetic Biology: Digital Design of Living Systems.' Christen will describe how computational algorithms paired with chemical DNA synthesis enable digital manufacturing of biological systems up to the size of entire microbial genomes.

Computer-based weather forecast: New algorithm outperforms mainframe computer systems
The exponential growth in computer processing power seen over the past 60 years may soon come to a halt.

A computer that understands how you feel
Neuroscientists have developed a brain-inspired computer system that can look at an image and determine what emotion it evokes in people.

Computer program looks five minutes into the future
Scientists from the University of Bonn have developed software that can look minutes into the future: The program learns the typical sequence of actions, such as cooking, from video sequences.

Computer redesigns enzyme
University of Groningen biotechnologists used a computational method to redesign aspartase and convert it to a catalyst for asymmetric hydroamination reactions.

Mining for gold with a computer
Engineers from Texas A&M University and Virginia Tech report important new insights into nanoporous gold -- a material with growing applications in several areas, including energy storage and biomedical devices -- all without stepping into a lab.

Teaching quantum physics to a computer
An international collaboration led by ETH physicists has used machine learning to teach a computer how to predict the outcomes of quantum experiments.

Read More: Computer News and Computer Current Events
Brightsurf.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.