Zeph: Cryptographic Enforcement of End-to-End Data Privacy
Lukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh, Anwar Hithnawi
Abstract
As increasingly more sensitive data is being collected to gain valuable insights, the need to natively integrate privacy controls in data analytics frameworks is growing in importance. Today, privacy controls are enforced by data curators with full access to data in the clear. However, a plethora of recent data breaches show that even widely trusted service providers can be compromised. Additionally, there is no assurance that data processing and handling comply with the claimed privacy policies. This motivates the need for a new approach to data privacy that can provide strong assurance and control to users. This paper presents Zeph, a system that enables users to set privacy preferences on how their data can be shared and processed. Zeph enforces privacy policies cryptographically and ensures that data available to third-party applications complies with users' privacy policies. Zeph executes privacy-adhering data transformations in real-time and scales to thousands of data sources, allowing it to support large-scale low-latency data stream analytics. We introduce a hybrid cryptographic protocol for privacy-adhering transformations of encrypted data. We develop a prototype of Zeph on Apache Kafka to demonstrate that Zeph can perform large-scale privacy transformations with low overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5bb8c0d6-400e-4410-9c20-eab2e7bc3018Cited by top-tier papers10
- Waldo: A Private Time-Series Database from Function Secret SharingEmma Dauterman, Mayank Rathee, Raluca Ada Popa, Ion StoicaS&P 2022 · 91 citations
- Vizard: A Metadata-hiding Data Analytic System with End-to-End Policy ControlsChengjun Cai, Yichen Zang, Cong Wang, Xiaohua Jia et al.CCS 2022 · 12 citations
- Synq: Public Policy Analytics Over Encrypted DataZachary Espiritu, Marilyn George, Seny Kamara, Lucy QinS&P 2024 · 8 citations
- K9db: Privacy-Compliant Storage For Web Applications By ConstructionKinan Dak Albab, Ishan Sharma, Justus Adam, Benjamin Kilimnik et al.OSDI 2023 · 7 citations
- Sesame: Practical End-to-End Privacy Compliance with Policy Containers and Privacy RegionsKinan Dak Albab, Artem Agvanian, Allen Aby, Corinn Tiffany et al.SOSP 2024 · 2 citations
Builds on7
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Global-Scale Secure Multiparty ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 220 citations
- SoK: Fully Homomorphic Encryption CompilersAlexander Viand, Patrick Jattke, Anwar HithnawiS&P 2021 · 117 citations
- Homomorphic Secret Sharing: Optimizations and ApplicationsElette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval Ishai et al.CCS 2017 · 97 citations
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
Related papers
- X-Stream: A Flexible, Adaptive Video Transformer for Privacy-Preserving Video Stream AnalyticsDou Feng, Lin Wang, Shutong Chen, Lingching Tung et al.INFOCOM 2024 · 8 citations
- TimeCrypt: Encrypted Data Stream Processing at Scale with Cryptographic Access ControlLukas Burkhalter, Anwar Hithnawi, Alexander Viand, Hossein Shafagh et al.NSDI 2020 · 18 citations
- PP-Stream: Toward High-Performance Privacy-Preserving Neural Network Inference via Distributed Stream ProcessingQingxiu Liu, Qun Huang, Xiang Chen, Sa Wang et al.ICDE 2024 · 8 citations
- TaintStream: fine-grained taint tracking for big data platforms through dynamic code translationChengxu Yang, Yuanchun Li, Mengwei Xu, Zhenpeng Chen et al.FSE 2021 · 11 citations
- Zero-Knowledge Cloud AnalyticsZeying Zhu, Clarence Lam, Alexander Frolov, Ian Miers et al.SIGCOMM 2026
