Compact Key Storage - A Modern Approach to Key Backup and Delegation
Yevgeniy Dodis, Daniel Jost, Antonio Marcedone
Abstract
End-to-End (E2E) encrypted messaging, which prevents even the service provider from learning communication contents, is gaining popularity. Since users care about maintaining access to their data even if their devices are lost or broken or just replaced, these systems are often paired with cloud backup solutions: Typically, the user will encrypt their messages with a fixed key, and upload the ciphertexts to the server. Unfortunately, this naive solution has many drawbacks. First, it often undermines the fancy security guarantees of the core application, such as forward secrecy (FS) and post-compromise security (PCS), in case the single backup key is compromised. Second, they are wasteful for backing up conversations in large groups, where many users are interested in backing up the same sequence of messages.
Instead, we formalize a new primitive called Compact Key Storage (CKS) as the "right" solution to this problem. Such CKS scheme allows a mutable set of parties to delegate to a server storage of an increasing set of keys, while each client maintains only a small state. Clients update their state as they learn new keys (maintaining PCS), or whenever they want to forget keys (achieving FS), often without the need to interact with the server. Moreover, access to the keys (or some subset of them) can be efficiently delegated to new group members, who all efficiently share the same server's storage.
We carefully define syntax, correctness, privacy, and integrity of CKS schemes, and build two efficient schemes provably satisfying these notions. Our line scheme covers the most basic "all-or-nothing" flavor of CKS, where one wishes to compactly store and delegate the entire history of past secrets. Thus, new users enjoy the efficiency and compactness properties of the CKS only after being granted access to the entire history of keys. In contrast, our interval scheme is only slightly less efficient but allows for finer-grained access, delegation, and deletion of past keys.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on7
- OptORAMa: Optimal Oblivious RAMGilad Asharov, Ilan Komargodski, Wei-Kai Lin, Kartik Nayak et al.EUROCRYPT 2020 · 92 citations
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 91 citations
- Mirror: Enabling Proofs of Data Replication and Retrievability in the CloudFrederik Armknecht, Ludovic Barman, Jens-Matthias Bohli, Ghassan O. KarameUSENIX Security 2016 · 53 citations
- Updatable Oblivious Key Management for Storage SystemsStanislaw Jarecki, Hugo Krawczyk, Jason K. ReschCCS 2019 · 52 citations
- Fast and Secure Updatable EncryptionColin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao JiangCRYPTO 2020 · 52 citations
Related papers
- Loom: Weaving PCS-Preserving and Searchable Cloud Backups for Secure MessagingTiancheng Zhu, Jiabei Wang, Yongbin ZhouSIGMOD 2026
- Group Key Progression: Strong Security for Shared Persistent DataMatilda Backendal, David Balbás, Miro HallerEUROCRYPT 2026
- SEEMless: Secure End-to-End Encrypted Messaging with less</> TrustMelissa Chase, Apoorvaa Deshpande, Esha Ghosh, Harjasleen MalvaiCCS 2019 · 69 citations
- Parakeet: Practical Key Transparency for End-to-End Encrypted MessagingHarjasleen Malvai, Lefteris Kokoris-Kogias, Alberto Sonnino, Esha Ghosh et al.NDSS 2023
- Key Agreement for Decentralized Secure Group Messaging with Strong Security GuaranteesMatthew Weidner, Martin Kleppmann, Daniel Hugenroth, Alastair R. BeresfordCCS 2021 · 28 citations
