arrow
Return

Accountable Decryption Made Formal and Practical

delete2025-01-01
delete0
PRE
AI
R
Rujia Li
Y
Yuanzhao Li
Q
Qin Wang *
S
Sisi Duan *
王琪 cover
王琪 (Qi Wang) *
M
Mark Ryan *
DOI:10.1109/TIFS.2024.3515808delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
With the increasing scale and complexity of online activities, accountability, as an after-the-fact mechanism, has become an effective complementary approach to ensure system security. Decades of research have delved into the connotation of accountability. They fail, however, to achieve practical accountability of decryption. This paper seeks to address this gap. We consider the scenario where a client (called encryptor, her) encrypts her data and then chooses a delegate (a.k.a. decryptor, him) that stores data for her. If the decryptor initiates an illegitimate decryption on the encrypted data, there is a non-negligible probability that this behavior will be detected, thereby holding the decryptor accountable for his decryption. We make three contributions. First, we review key definitions of accountability known so far. Based on extensive investigations, we formalize new definitions of accountability specifically targeting the decryption process, denoted as accountable decryption, and discuss the (im)possibilities when capturing this concept. We also define the security goals in correspondence. Second, we present a novel Trusted Execution Environment(TEE)-assisted solution aligning with definitions. Instead of fully trusting TEE, we take a further step, making TEE work in the trust, but verify model where we trust TEE and use its service, but empower users (i.e., decryptors) to detect the potentially compromised state of TEEs. Third, we implement a full-fledged system and conduct a series of evaluations. The results demonstrate that our solution is efficient. Even in a scenario involving $300,000$ log entries, the decryption process concludes in approximately 5.5ms, and malicious decryptors can be identified within 69ms.
Keywords:
Cryptography
Hardware
Security
Reviews
Surveillance
Software
Runtime
Government
Games
Complexity theory
Accountability
decryption
trusted hardware

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

T
tsinghua university
Scholars:
11.8W
Papers: 10.0W
Citations: 137