USENIX Security2021Top-tier venue
Protecting Cryptography Against Compelled Self-Incrimination
Sarah Scheffler, Mayank Varia
Abstract
The information security community has devoted substantial effort to the design, development, and universal deployment of strong encryption schemes that withstand search and seizure by computationallypowerful nation-state adversaries. In response, governments are increasingly turning to a different tactic: issuing subpoenas that compel people to decrypt devices themselves, under the penalty of contempt of court if they do not comply. Compelled decryption subpoenas sidestep questions around government search powers that have dominated the Crypto Wars and instead touch upon a different (and still unsettled) area of the law: how encryption relates to a person's right to silence and against self-incrimination. In this work, we provide a rigorous, composable definition of a critical piece of the law that determines whether cryptosystems are vulnerable to government compelled disclosure in the United States. We justify our definition by showing that it is consistent with prior court cases. We prove that decryption is often not compellable by the government under our definition. Conversely, we show that many techniques that bolster security overall can leave one more vulnerable to compelled disclosure. As a result, we initiate the study of protecting cryptographic protocols against the threat of future compelled disclosure. We find that secure multi-party computation is particularly vulnerable to this threat, and we design and implement new schemes that are provably resilient in the face of government compelled disclosure. We believe this work should influence the design of future cryptographic primitives and contribute toward the legal debates over the constitutionality of compelled decryption.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 23abb775-d7ad-4aba-9ccd-f654e39698ccBuilds on5
- Authenticated Garbling and Efficient Maliciously Secure Two-Party ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 212 citations
- Practical Accountability of Secret ProcessesJonathan Frankle, Sunoo Park, Daniel Shaar, Shafi Goldwasser et al.USENIX Security 2018 · 63 citations
- Lawful Device Access without Mass Surveillance Risk: A Technical Design DiscussionStefan SavageCCS 2018 · 22 citations
- BurnBox: Self-Revocable Encryption in a World Of Compelled AccessNirvan Tyagi, Muhammad Haris Mughees, Thomas Ristenpart, Ian MiersUSENIX Security 2018 · 10 citations
- Formalizing Data Deletion in the Context of the Right to Be ForgottenSanjam Garg, Shafi Goldwasser, Prashant Nalini VasudevanEUROCRYPT 2020 · 7 citations
Related papers
- Anamorphic Encryption: Private Communication Against a DictatorGiuseppe Persiano, Duong Hieu Phan, Moti YungEUROCRYPT 2022 · 45 citations
- Estimating Incidental Collection in Foreign Intelligence Surveillance: Large-Scale Multiparty Private Set Intersection with Union and SumAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2022
- Anamorphic-Resistant Encryption; Or Why the Encryption Debate is Still AliveYevgeniy Dodis, Eli GoldinCRYPTO 2025 · 8 citations
- A Decentralized and Encrypted National Gun RegistrySeny Kamara, Tarik Moataz, Andrew Park, Lucy QinS&P 2021 · 33 citations
- Cryptographic Deniability: A Multi-perspective Study of User Perceptions and ExpectationsTarun Kumar Yadav, Devashish Gosain, Kent E. SeamonsUSENIX Security 2023
