CSIS-数字键交易的加密范围:基于安全性的考虑(英文)-2020.8-47页_11mb
报告摘要
Summary of "The Spectrum of Encryption"
Core Content
This report by the Center for Strategic and International Studies (CSIS) examines the global landscape of encryption policy, focusing on the diverse needs and concerns of different user communities. It highlights the growing tension between the need for law enforcement access to encrypted data and the protection of individual privacy and freedoms.
Main Views and Key Information
Encryption's Role and Importance
- Encryption is a critical tool for protecting sensitive information, preventing cybercrime, and authenticating digital transactions.
- It is used in various forms, including:
- Data at rest: Stored on devices.
- Data in transit: Communications between users, devices, and applications.
- Unrecoverable encryption, which requires users to have private keys for access, is increasingly common and used by major OS families (Android and iOS) and instant messaging platforms.
Policy Dilemmas
- Lawful access to encrypted data is a major challenge for policymakers in the U.S. and other democracies.
- The "Going Dark" problem refers to the difficulty law enforcement faces in accessing encrypted data, which is a growing concern due to the increasing use of encryption in daily life.
- Governments are concerned about the implications of unrecoverable encryption on public safety, national security, and the ability to investigate crimes.
User Communities and Their Needs
The report identifies five key user communities and analyzes their perspectives and needs regarding encryption:
-
Independent Voices (e.g., journalists, activists, NGOs)
- These groups rely on encryption to protect their communications from state surveillance and other forms of monitoring.
- They value privacy and free speech, and encryption is essential for their work.
-
At-risk Groups (e.g., minorities, dissidents, vulnerable populations)
- These users often face repression and require encryption to protect their activities and communications.
- They may be targeted by authoritarian regimes, which impose strict encryption mandates to monitor and control citizens.
-
Businesses and Organizations
- They use encryption to secure data at rest and data in transit.
- They also prioritize user privacy and cybersecurity.
-
Foreign Policy Practitioners (e.g., diplomats, military and intelligence officers)
- These groups use encryption to protect sensitive communications and national security interests.
- They may face challenges in accessing encrypted data across borders.
-
Terrorists, Extremists, and Hate Groups
- These groups use encryption to coordinate and plan attacks.
- Encryption can be a tool for harm, making it a challenge for public safety and national security.
Encryption Policy Environments
The report outlines five broad categories of encryption policy environments:
- Design Mandates: Require companies to build systems in ways that allow government access. Examples include Russia and China, which enforce strict encryption standards and mandates.
- Technology-neutral Access Mandates: Do not specify encryption methods but require companies to provide decrypted data to the government. France and UK have such laws.
- User Decryption Mandates: Compel users to disclose their encryption keys. Australia and France have implemented such policies.
- Workarounds to Access Encrypted Data: Governments use methods like lawful hacking and man-in-the-middle attacks to access encrypted data. Germany has developed legal frameworks for this.
- No Access to Encrypted Communications: Some countries lack legal authorities to access encrypted data, leading to regulatory uncertainty and trust issues among users. The U.S. is an example of this environment.
Implications and Challenges
- Legal authorities over encryption are often unclear, leading to regulatory uncertainty and ethical dilemmas.
- Foreign companies may face inconsistent enforcement or arbitrary application of encryption laws in countries with unclear mandates.
- User trust in encryption platforms is compromised when governments impose unreasonable access demands.
- Global encryption policies affect U.S. citizens and businesses, requiring the U.S. to set norms and standards to protect its interests.
Conclusion
The report concludes that encryption policy must be nuanced and context-specific, balancing the needs of privacy, cybersecurity, public safety, and national security. The choices made by countries regarding encryption will have global implications, influencing how companies build products and how users access encryption tools. The U.S. has a role in shaping global norms to protect its citizens, businesses, and values in an increasingly digital world.
About the Authors
- Lindsey R. Sheppard
- Brian Katz
- Kathleen H. Hicks
- Joseph Federici
These authors are affiliated with the International Security Program at CSIS, a leading think tank focused on national security and policy research. Their work emphasizes the importance of nonpartisan, cross-disciplinary scholarship in addressing global challenges.
试读结束,高清完整版pdf/doc/ppt,请点下载