Updatable Oblivious Key Management for Storage Systems
Stanislaw Jarecki, Hugo Krawczyk, Jason K. Resch
Abstract
We introduce Oblivious Key Management Systems (KMS) as a much more secure alternative to traditional wrapping-based KMS that form the backbone of key management in large-scale data storage deployments. The new system, that builds on Oblivious Pseudorandom Functions (OPRF), hides keys and object identifiers from the KMS, offers unconditional security for key transport, provides key verifiability, reduces storage, and more. Further, we show how to provide all these features in a distributed threshold implementation that enhances protection against server compromise. We extend this system with updatable encryption capability that supports key updates (known as key rotation) so that upon the periodic change of OPRF keys by the KMS server, a very efficient update procedure allows a client of the KMS service to non-interactively update all its encrypted data to be decryptable only by the new key. This enhances security with forward and post-compromise security, namely, security against future and past compromises, respectively, of the client's OPRF keys held by the KMS. Additionally, and in contrast to traditional KMS, our solution supports public key encryption and dispenses with any interaction with the KMS for data encryption (only decryption by the client requires such communication). Our solutions build on recent work on updatable encryption but with significant enhancements applicable to the remote KMS setting. In addition to the critical security improvements, our designs are highly efficient and ready for use in practice. We report on experimental implementation and performance. CCS CONCEPTS • Security and privacy → Key management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a5f4f1e4-41ac-40e6-9c8c-a49e8df1d1b5Cited by top-tier papers5
- Fast and Secure Updatable EncryptionColin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao JiangCRYPTO 2020 · 52 citations
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 2 citations
- End-to-Same-End Encryption: Modularly Augmenting an App with an Efficient, Portable, and Blind Cloud StorageLong Chen, Ya-Nan Li, Qiang Tang, Moti YungUSENIX Security 2022
- Amortized Threshold Symmetric-key EncryptionMihai Christodorescu, Sivanarayana Gaddam, Pratyay Mukherjee, Rohit SinhaCCS 2021
- Gold OPRF: Post-Quantum Oblivious Power-Residue PRFYibin Yang, Fabrice Benhamouda, Shai Halevi, Hugo Krawczyk et al.S&P 2025
Builds on1
Related papers
- A Fully-Adaptive Threshold Partially-Oblivious PRFRuben Baecker, Paul Gerhart, Daniel Rausch, Dominique SchröderCRYPTO 2025 · 1 citation
- High-throughput Verifiable Distributed OPRF from Gold PRFNan Cheng, Yohei Watanabe, Yugo Kasashima, Ioannis Katis et al.CCS 2026
- Updatable Public Key Encryption from DCR: Efficient Constructions With Stronger SecurityCalvin Abou Haidar, Benoît Libert, Alain PasselègueCCS 2022 · 7 citations
- OPTIKS: An Optimized Key Transparency SystemJulia Len, Melissa Chase, Esha Ghosh, Kim Laine et al.USENIX Security 2024 · 18 citations
- LaKey: Efficient Lattice-Based Distributed PRFs Enable Scalable Distributed Key ManagementMatthias Geihs, Hart MontgomeryUSENIX Security 2024 · 7 citations
