{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T10:24:06Z","timestamp":1781519046531,"version":"3.54.1"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2009,6,1]],"date-time":"2009-06-01T00:00:00Z","timestamp":1243814400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Petascale Data Storage Institute","award":["FC02-06ER25768"],"award-info":[{"award-number":["FC02-06ER25768"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Storage"],"published-print":{"date-parts":[[2009,6]]},"abstract":"<jats:p>Users are storing ever-increasing amounts of information digitally, driven by many factors including government regulations and the public's desire to digitally record their personal histories. Unfortunately, many of the security mechanisms that modern systems rely upon, such as encryption, are poorly suited for storing data for indefinitely long periods of time; it is very difficult to manage keys and update cryptosystems to provide secrecy through encryption over periods of decades. Worse, an adversary who can compromise an archive need only wait for cryptanalysis techniques to catch up to the encryption algorithm used at the time of the compromise in order to obtain \u201csecure\u201d data. To address these concerns, we have developed POTSHARDS, an archival storage system that provides long-term security for data with very long lifetimes without using encryption. Secrecy is achieved by using unconditionally secure secret splitting and spreading the resulting shares across separately managed archives. Providing availability and data recovery in such a system can be difficult; thus, we use a new technique, approximate pointers, in conjunction with secure distributed RAID techniques to provide availability and reliability across independent archives. To validate our design, we developed a prototype POTSHARDS implementation. In addition to providing us with an experimental testbed, this prototype helped us to understand the design issues that must be addressed in order to maximize security.<\/jats:p>","DOI":"10.1145\/1534912.1534914","type":"journal-article","created":{"date-parts":[[2009,6,9]],"date-time":"2009-06-09T12:44:12Z","timestamp":1244551452000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":49,"title":["POTSHARDS\u2014a secure, recoverable, long-term archival storage system"],"prefix":"10.1145","volume":"5","author":[{"given":"Mark W.","family":"Storer","sequence":"first","affiliation":[{"name":"University of California, Santa Cruz, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kevin M.","family":"Greenan","sequence":"additional","affiliation":[{"name":"University of California, Santa Cruz, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ethan L.","family":"Miller","sequence":"additional","affiliation":[{"name":"University of California, Santa Cruz, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kaladhar","family":"Voruganti","sequence":"additional","affiliation":[{"name":"NetApp, Sunnyvale, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2009,6,12]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Congress.","year":"1996","unstructured":"104th Congress. 1996 . Health Information Portability and Accountability Act. http:\/\/www.hhs.gov\/ocr\/hipaa\/. 104th Congress. 1996. Health Information Portability and Accountability Act. http:\/\/www.hhs.gov\/ocr\/hipaa\/."},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the 5th Symposium on Operating Systems Design and Implementation (OSDI). USENIX.","author":"Adya A.","unstructured":"Adya , A. , Bolosky , W. J. , Castro , M. , Chaiken , R. , Cermak , G. , Douceur , J. R. , Howell , J. , Lorch , J. R. , Theimer , M. , and Wattenhofer , R . 2002. FARSITE: Federated, available, and reliable storage for an incompletely trusted environment . In Proceedings of the 5th Symposium on Operating Systems Design and Implementation (OSDI). USENIX. Adya, A., Bolosky, W. J., Castro, M., Chaiken, R., Cermak, G., Douceur, J. R., Howell, J., Lorch, J. R., Theimer, M., and Wattenhofer, R. 2002. FARSITE: Federated, available, and reliable storage for an incompletely trusted environment. In Proceedings of the 5th Symposium on Operating Systems Design and Implementation (OSDI). USENIX."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217957"},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the Advances in Cryptology 6th International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT'00)","volume":"1976","author":"Bellare M.","unstructured":"Bellare , M. and Boldyreva , A . 2000. The security of chaffing and winnowing . In Proceedings of the Advances in Cryptology 6th International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT'00) . Lecure Notes in Computer Science , vol. 1976 , Springer, Berlin, 517--530. Bellare, M. and Boldyreva, A. 2000. The security of chaffing and winnowing. In Proceedings of the Advances in Cryptology 6th International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT'00). Lecure Notes in Computer Science, vol. 1976, Springer, Berlin, 517--530."},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the 12th USENIX Security Symposium, 105--120","author":"Bhatkar S.","unstructured":"Bhatkar , S. , DuVarney , D. C. , and Sekar , R . 2003. Address obfuscation: An effcient approach to combat a broad range of memory error exploits . In Proceedings of the 12th USENIX Security Symposium, 105--120 . Bhatkar, S., DuVarney, D. C., and Sekar, R. 2003. Address obfuscation: An effcient approach to combat a broad range of memory error exploits. In Proceedings of the 12th USENIX Security Symposium, 105--120."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the Conference on File and Storage Technologies (FAST). 103--116","author":"Chang F.","unstructured":"Chang , F. , Ji , M. , Leung , S.-T. A. , MacCormick , J. , Perl , S. E. , and Zhang , L . 2002. Myriad: Cost-Effective disaster tolerance . In Proceedings of the Conference on File and Storage Technologies (FAST). 103--116 . Chang, F., Ji, M., Leung, S.-T. A., MacCormick, J., Perl, S. E., and Zhang, L. 2002. Myriad: Cost-Effective disaster tolerance. In Proceedings of the Conference on File and Storage Technologies (FAST). 103--116."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/1757599.1757710"},{"key":"e_1_2_1_8_1","series-title":"Lecture Notes in Computer Science","volume-title":"Freenet: A distributed anonymous information storage and retrieval system","author":"Clarke I.","year":"2001","unstructured":"Clarke , I. , Sandberg , O. , Wiley , B. , and Hong, T. W. 2001 . Freenet: A distributed anonymous information storage and retrieval system . Lecture Notes in Computer Science , vol. 2009 , 46--66. Clarke, I., Sandberg, O., Wiley, B., and Hong, T. W. 2001. Freenet: A distributed anonymous information storage and retrieval system. Lecture Notes in Computer Science, vol. 2009, 46--66."},{"key":"e_1_2_1_9_1","unstructured":"CleverSafe. 2006. Highly secure highly reliable open source storage solution. http:\/\/www. cleversafe.org\/.  CleverSafe. 2006. Highly secure highly reliable open source storage solution. http:\/\/www. cleversafe.org\/."},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the 6th Workshop on Hot Topics in Operating Systems (HotOS-VI), 67--72","author":"Forrest S.","unstructured":"Forrest , S. , Somayaji , A. , and Ackley , D. H . 1997. Building diverse systems . In Proceedings of the 6th Workshop on Hot Topics in Operating Systems (HotOS-VI), 67--72 . Forrest, S., Somayaji, A., and Ackley, D. H. 1997. Building diverse systems. In Proceedings of the 6th Workshop on Hot Topics in Operating Systems (HotOS-VI), 67--72."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1080343.1080346"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the Conference on Advances in Digital Libraries (ADL'98)","author":"Goldberg A. V.","unstructured":"Goldberg , A. V. and Yianilos , P. N . 1998. Towards an archival intermemory . In Proceedings of the Conference on Advances in Digital Libraries (ADL'98) , 1--9. Goldberg, A. V. and Yianilos, P. N. 1998. Towards an archival intermemory. In Proceedings of the Conference on Advances in Digital Libraries (ADL'98), 1--9."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the International Conference on Dependable Systems and Networking (DSN'04)","author":"Goodson G. R.","unstructured":"Goodson , G. R. , Wylie , J. J. , Ganger , G. R. , and Reiter , M. K . 2004. Efficient Byzantine-tolerant erasure-coded storage . In Proceedings of the International Conference on Dependable Systems and Networking (DSN'04) . Goodson, G. R., Wylie, J. J., Ganger, G. R., and Reiter, M. K. 2004. Efficient Byzantine-tolerant erasure-coded storage. In Proceedings of the International Conference on Dependable Systems and Networking (DSN'04)."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2005.20"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the 2nd Symposium on Networked Systems Design and Implementation (NSDI). USENIX.","author":"Haeberlen A.","unstructured":"Haeberlen , A. , Mislove , A. , and Druschel , P . 2005. Glacier: Highly durable, decentralized storage despite massive correlated failures . In Proceedings of the 2nd Symposium on Networked Systems Design and Implementation (NSDI). USENIX. Haeberlen, A., Mislove, A., and Druschel, P. 2005. Glacier: Highly durable, decentralized storage despite massive correlated failures. In Proceedings of the 2nd Symposium on Networked Systems Design and Implementation (NSDI). USENIX."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/646334.756802"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 14th IFIP International Information Security Conference (SEC'98)","author":"Iyengar A.","unstructured":"Iyengar , A. , Cahn , R. , Garay , J. A. , and Jutla , C . 1998. Design and implementation of a secure distributed data repository . In Proceedings of the 14th IFIP International Information Security Conference (SEC'98) , 123--135. Iyengar, A., Cahn, R., Garay, J. A., and Jutla, C. 1998. Design and implementation of a secure distributed data repository. In Proceedings of the 14th IFIP International Information Security Conference (SEC'98), 123--135."},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST). USENIX, 29--42","author":"Kallahalla M.","unstructured":"Kallahalla , M. , Riedel , E. , Swaminathan , R. , Wang , Q. , and Fu , K . 2003. Plutus: Scalable secure file sharing on untrusted storage . In Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST). USENIX, 29--42 . Kallahalla, M., Riedel, E., Swaminathan, R., Wang, Q., and Fu, K. 2003. Plutus: Scalable secure file sharing on untrusted storage. In Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST). USENIX, 29--42."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 3rd USENIX Conference on File and Storage Technologies (FAST).","author":"Keeton K.","unstructured":"Keeton , K. , Santos , C. , Beyer , D. , Chase , J. , and Wilkes , J . 2004. Designing for disasters . In Proceedings of the 3rd USENIX Conference on File and Storage Technologies (FAST). Keeton, K., Santos, C., Beyer, D., Chase, J., and Wilkes, J. 2004. Designing for disasters. In Proceedings of the 3rd USENIX Conference on File and Storage Technologies (FAST)."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the USENIX Annual Technical Conference, 129--142","author":"Kotla R.","unstructured":"Kotla , R. , Alvisi , L. , and Dahlin , M . 2007. SafeStore: A durable and practical storage system . In Proceedings of the USENIX Annual Technical Conference, 129--142 . Kotla, R., Alvisi, L., and Dahlin, M. 2007. SafeStore: A durable and practical storage system. In Proceedings of the USENIX Annual Technical Conference, 129--142."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1047915.1047917"},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the Conference on File and Storage Technologies (FAST), 1--13","author":"Miller E. L.","unstructured":"Miller , E. L. , Long , D. D. E. , Freeman , W. E. , and Reed , B. C . 2002. Strong security for network-attached storage . In Proceedings of the Conference on File and Storage Technologies (FAST), 1--13 . Miller, E. L., Long, D. D. E., Freeman, W. E., and Reed, B. C. 2002. Strong security for network-attached storage. In Proceedings of the Conference on File and Storage Technologies (FAST), 1--13."},{"key":"e_1_2_1_24_1","unstructured":"Oxley M. G. 2002. (H.R.3763) Sarbanes-Oxley Act of 2002.  Oxley M. G. 2002. (H.R.3763) Sarbanes-Oxley Act of 2002."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1002\/(SICI)1097-024X(199709)27:9%3C995::AID-SPE111%3E3.3.CO;2-Y"},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the Conference on File and Storage Technologies (FAST). USENIX. 89--101","author":"Quinlan S.","unstructured":"Quinlan , S. and Dorward , S . 2002. Venti: A new approach to archival storage . In Proceedings of the Conference on File and Storage Technologies (FAST). USENIX. 89--101 . Quinlan, S. and Dorward, S. 2002. Venti: A new approach to archival storage. In Proceedings of the Conference on File and Storage Technologies (FAST). USENIX. 89--101."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/62044.62050"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST), 1--14","author":"Rhea S.","unstructured":"Rhea , S. , Eaton , P. , Geels , D. , Weatherspoon , H. , Zhao , B. , and Kubiatowicz , J . 2003. Pond: The OceanStore prototype . In Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST), 1--14 . Rhea, S., Eaton, P., Geels, D., Weatherspoon, H., Zhao, B., and Kubiatowicz, J. 2003. Pond: The OceanStore prototype. In Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST), 1--14."},{"key":"e_1_2_1_29_1","first-page":"12","article-title":"Chaffing and winnowing: Confidentiality without encryption","volume":"4","author":"Rivest R. L.","year":"1998","unstructured":"Rivest , R. L. 1998 . Chaffing and winnowing: Confidentiality without encryption . CryptoBytes , 4 , 1, 12 -- 17 . Rivest, R. L. 1998. Chaffing and winnowing: Confidentiality without encryption. CryptoBytes, 4, 1, 12--17.","journal-title":"CryptoBytes"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/319151.319159"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2006.80"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359176"},{"key":"e_1_2_1_33_1","volume-title":"Cryptography: Theory and Practive","author":"Stinson D. R.","year":"2002","unstructured":"Stinson , D. R. 2002 . Cryptography: Theory and Practive , 2 nd ed. The CRC Press Series on Discrete Mathematics and its Applications. Chapman and Hall (CRC) , Boca Raton, FL. Stinson, D. R. 2002. Cryptography: Theory and Practive, 2nd ed. The CRC Press Series on Discrete Mathematics and its Applications. Chapman and Hall (CRC), Boca Raton, FL.","edition":"2"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 6th International Conference on Data Engineering (ICDE'90)","author":"Stonebraker M.","unstructured":"Stonebraker , M. and Schloss , G. A . 1990. Distributed RAID\u2014A new multiple copy algorithm . In Proceedings of the 6th International Conference on Data Engineering (ICDE'90) , 430--437. Stonebraker, M. and Schloss, G. A. 1990. Distributed RAID\u2014A new multiple copy algorithm. In Proceedings of the 6th International Conference on Data Engineering (ICDE'90), 430--437."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SISW.2005.10"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1179559.1179562"},{"key":"e_1_2_1_37_1","volume-title":"Proceedings of the USENIX Annual Technical Conference, 143--156","author":"Storer M. W.","unstructured":"Storer , M. W. , Greenan , K. M. , Miller , E. L. , and Voruganti , K . 2007. POTSHARDS: Secure long-term storage without encryption . In Proceedings of the USENIX Annual Technical Conference, 143--156 . Storer, M. W., Greenan, K. M., Miller, E. L., and Voruganti, K. 2007. POTSHARDS: Secure long-term storage without encryption. In Proceedings of the USENIX Annual Technical Conference, 143--156."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1103780.1103793"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456469.1456476"},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the 9th USENIX Security Symposium.","author":"Waldman M.","unstructured":"Waldman , M. , Rubin , A. D. , and Cranor , L. F . 2000. Publius: A robust, tamper-evident, censorship-resistant Web publishing system . In Proceedings of the 9th USENIX Security Symposium. Waldman, M., Rubin, A. D., and Cranor, L. F. 2000. Publius: A robust, tamper-evident, censorship-resistant Web publishing system. In Proceedings of the 9th USENIX Security Symposium."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180412"},{"key":"e_1_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Wong T. M. Wang C. and Wing J. M. 2002. Verifiable secret redistribution for threshold sharing schemes. Tech. rep. CMU-CS-02-114-R Carnegie Mellon University. October.  Wong T. M. Wang C. and Wing J. M. 2002. Verifiable secret redistribution for threshold sharing schemes. Tech. rep. CMU-CS-02-114-R Carnegie Mellon University. October.","DOI":"10.21236\/ADA461227"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.863969"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102151"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2005.47"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1243418.1243423"}],"container-title":["ACM Transactions on Storage"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1534912.1534914","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1534912.1534914","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:26:06Z","timestamp":1750278366000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1534912.1534914"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,6]]},"references-count":46,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2009,6]]}},"alternative-id":["10.1145\/1534912.1534914"],"URL":"https:\/\/doi.org\/10.1145\/1534912.1534914","relation":{},"ISSN":["1553-3077","1553-3093"],"issn-type":[{"value":"1553-3077","type":"print"},{"value":"1553-3093","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,6]]},"assertion":[{"value":"2008-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-02-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-06-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}