{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T16:33:18Z","timestamp":1783528398683,"version":"3.55.0"},"reference-count":21,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2009,3,1]],"date-time":"2009-03-01T00:00:00Z","timestamp":1235865600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Storage"],"published-print":{"date-parts":[[2009,3]]},"abstract":"<jats:p>The need for secure logging is well-understood by the security professionals, including both researchers and practitioners. The ability to efficiently verify all (or some) log entries is important to any application employing secure logging techniques. In this article, we begin by examining the state of the art in secure logging and identify some problems inherent to systems based on trusted third-party servers. We then propose a different approach to secure logging based upon recently developed Forward-Secure Sequential Aggregate (FssAgg) authentication techniques. Our approach offers both space-efficiency and provable security. We illustrate two concrete schemes\u2014one private-verifiable and one public-verifiable\u2014that offer practical secure logging without any reliance on online trusted third parties or secure hardware. We also investigate the concept of immutability in the context of forward-secure sequential aggregate authentication to provide finer grained verification. Finally we evaluate proposed schemes and report on our experience with implementing them within a secure logging system.<\/jats:p>","DOI":"10.1145\/1502777.1502779","type":"journal-article","created":{"date-parts":[[2009,4,6]],"date-time":"2009-04-06T16:34:22Z","timestamp":1239035662000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":110,"title":["A new approach to secure logging"],"prefix":"10.1145","volume":"5","author":[{"given":"Di","family":"Ma","sequence":"first","affiliation":[{"name":"University of California, Irvine"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gene","family":"Tsudik","sequence":"additional","affiliation":[{"name":"University of California, Irvine"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2009,3,31]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Bellare M. and Palacio A. 2002. Protecting against key exposure: strongly key-insulated encryption with optimal threshold. In Cryptology ePrint Archive Report 2002\/64.  Bellare M. and Palacio A. 2002. Protecting against key exposure: strongly key-insulated encryption with optimal threshold. In Cryptology ePrint Archive Report 2002\/64."},{"key":"e_1_2_1_2_1","unstructured":"Bellare M. and Yee B. 1997. Forward integrity for secure audit logs. Tech. rep. University of California at San Diego ftp:\/\/www.cs.ucsd.edu\/pub\/bsq\/pub\/fi.ps.  Bellare M. and Yee B. 1997. Forward integrity for secure audit logs. Tech. rep. University of California at San Diego ftp:\/\/www.cs.ucsd.edu\/pub\/bsq\/pub\/fi.ps."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the RSA Conference Cryptography Track.","author":"Bellare M.","unstructured":"Bellare , M. and Yee , B . 2003. Forward-security in private-key cryptography . In Proceedings of the RSA Conference Cryptography Track. Bellare, M. and Yee, B. 2003. Forward-security in private-key cryptography. In Proceedings of the RSA Conference Cryptography Track."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1103780.1103787"},{"key":"e_1_2_1_5_1","unstructured":"Chong C. Peng Z. and Hartel P. 2002. Secure audit logging with tamper resistant hardware. In Technical Rep. TR-CTIT-02-29 Centre for Telematics and Information Technology Univ. Twente The Netherlands.  Chong C. Peng Z. and Hartel P. 2002. Secure audit logging with tamper resistant hardware. In Technical Rep. TR-CTIT-02-29 Centre for Telematics and Information Technology Univ. Twente The Netherlands."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the Annual International Conference on Theory and Practice of Cryptographic Technique (Eurocrypt'02)","author":"Dodis Y.","unstructured":"Dodis , Y. , Katz , J. , Xu , S. , and Yung , M . 2002. Key-insulated public key cryptosystems . In Proceedings of the Annual International Conference on Theory and Practice of Cryptographic Technique (Eurocrypt'02) . 65--82. Dodis, Y., Katz, J., Xu, S., and Yung, M. 2002. Key-insulated public key cryptosystems. In Proceedings of the Annual International Conference on Theory and Practice of Cryptographic Technique (Eurocrypt'02). 65--82."},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the Conference on Public Key Cryptography. 130--144","author":"Dodis Y.","unstructured":"Dodis , Y. , Katz , J. , Xu , S. , and Yung , M . 2003. Strong key-insulated public key cryptosystems . In Proceedings of the Conference on Public Key Cryptography. 130--144 . Dodis, Y., Katz, J., Xu, S., and Yung, M. 2003. Strong key-insulated public key cryptosystems. In Proceedings of the Conference on Public Key Cryptography. 130--144."},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the 6th USENIX Security Symposium. 22--25","author":"Gutmann P.","year":"1996","unstructured":"Gutmann , P. 1996 . Secure deletion of data from magnetic and solid-state memory . In Proceedings of the 6th USENIX Security Symposium. 22--25 . Gutmann, P. 1996. Secure deletion of data from magnetic and solid-state memory. In Proceedings of the 6th USENIX Security Symposium. 22--25."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2008.16"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the 2006 Australasian Workshops on Grid Computing and E-Research. 203--211","author":"Holt J.","year":"2006","unstructured":"Holt , J. 2006 . Logcrypt: forward security and public verification for secure audit logs . In Proceedings of the 2006 Australasian Workshops on Grid Computing and E-Research. 203--211 . Holt, J. 2006. Logcrypt: forward security and public verification for secure audit logs. In Proceedings of the 2006 Australasian Workshops on Grid Computing and E-Research. 203--211."},{"key":"e_1_2_1_11_1","volume-title":"Proceedings of the Recent Advances in Intrusion Detection (RAID'99)","author":"Kelsey J.","unstructured":"Kelsey , J. and Schneier , B . 1999. Minimizing bandwidth for remote access to cryptographically protected audit logs . In Proceedings of the Recent Advances in Intrusion Detection (RAID'99) . Kelsey, J. and Schneier, B. 1999. Minimizing bandwidth for remote access to cryptographically protected audit logs. In Proceedings of the Recent Advances in Intrusion Detection (RAID'99)."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368310.1368361"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.18"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70567-3_4"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the ACM Annual Symposium on Network and Distributed System Security (NDSS'04)","author":"Mykletun E.","unstructured":"Mykletun , E. , Narasimha , M. , and Tsudik , G . 2004a. Authentication and integrity in outsourced databases . In Proceedings of the ACM Annual Symposium on Network and Distributed System Security (NDSS'04) . Mykletun, E., Narasimha, M., and Tsudik, G. 2004a. Authentication and integrity in outsourced databases. In Proceedings of the ACM Annual Symposium on Network and Distributed System Security (NDSS'04)."},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS'04)","author":"Mykletun E.","unstructured":"Mykletun , E. , Narasimha , M. , and Tsudik , G . 2004b. Signature bouquets: immutability for aggreagated\/codensed signatures . In Proceedings of the European Symposium on Research in Computer Security (ESORICS'04) . 160--176. Mykletun, E., Narasimha, M., and Tsudik, G. 2004b. Signature bouquets: immutability for aggreagated\/codensed signatures. In Proceedings of the European Symposium on Research in Computer Security (ESORICS'04). 160--176."},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 7th USENIX Security Symposium.","author":"Schneier B.","unstructured":"Schneier , B. and Kelsey , J . 1998. Cryptographic support for secure logs on untrusted machines . Proceedings of the 7th USENIX Security Symposium. Schneier, B. and Kelsey, J. 1998. Cryptographic support for secure logs on untrusted machines. Proceedings of the 7th USENIX Security Symposium."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/317087.317089"},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Swanson M. and Guttman B. 1996. Generally accepted principles and practices for securing information technology systems. In National Institute of Standards and Technology Data Gateway 800--14.   Swanson M. and Guttman B. 1996. Generally accepted principles and practices for securing information technology systems. In National Institute of Standards and Technology Data Gateway 800--14.","DOI":"10.6028\/NIST.SP.800-14"},{"key":"e_1_2_1_20_1","unstructured":"U.S. Department of Defense C. S. C. 1985. Trusted computer system evaluation criteria.  U.S. Department of Defense C. S. C. 1985. Trusted computer system evaluation criteria."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the ACM Annual Symposium on Network and Distributed System Security (NDSS'04)","author":"Waters B.","unstructured":"Waters , B. , Balfanz , D. , Durfee , G. , and Smeters , D. K . 2004. Building an encrypted and searchable audit log . In Proceedings of the ACM Annual Symposium on Network and Distributed System Security (NDSS'04) . Waters, B., Balfanz, D., Durfee, G., and Smeters, D. K. 2004. Building an encrypted and searchable audit log. In Proceedings of the ACM Annual Symposium on Network and Distributed System Security (NDSS'04)."}],"container-title":["ACM Transactions on Storage"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1502777.1502779","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1502777.1502779","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:29:36Z","timestamp":1750253376000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1502777.1502779"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,3]]},"references-count":21,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2009,3]]}},"alternative-id":["10.1145\/1502777.1502779"],"URL":"https:\/\/doi.org\/10.1145\/1502777.1502779","relation":{},"ISSN":["1553-3077","1553-3093"],"issn-type":[{"value":"1553-3077","type":"print"},{"value":"1553-3093","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,3]]},"assertion":[{"value":"2008-05-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-03-31","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}