Flock: A Framework for Deploying On-Demand Distributed Trust
Darya Kaviani, Sijun Tan, Pravein Govindan Kannan, Raluca Ada Popa
Abstract
Recent years have exhibited an increase in applications that distribute trust across n servers to protect user data from a central point of attack. However, these deployments remain limited due to a core obstacle: establishing n distinct trust domains. An application provider, a single trust domain, cannot directly deploy multiple trust domains. As a result, application providers forge business relationships to enlist third-parties as trust domains, which is a manual, lengthy, and expensive process, inaccessible to many application developers.
We introduce the on-demand distributed-trust architecture that enables an application provider to deploy distributed trust automatically and immediately without controlling the other trust domains. The insight lies in reversing the deployment method such that each user's client drives deployment instead of the application provider. While at a first glance, this approach appears infeasible due to cost, performance, and resource abuse concerns, our system Flock resolves these challenges. We implement and evaluate Flock on 3 major cloud providers and 8 distributed-trust applications. On average, Flock achieves 1.05x the latency and 0.68-2.27x the cloud cost of a traditional distributed-trust deployment, without reliance on third-party relationships.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- ORQ: Complex Analytics on Private Data with Strong Security GuaranteesEli Baum, Sam Buxbaum, Nitin Mathai, Muhammad Faisal et al.SOSP 2025 · 4 citations
- C rypt D ough : A Unified Analytics Engine for Secure Multiparty ComputationMuhammad Faisal, Alessandra Lanz, Sam Buxbaum, Adam Godel et al.SOSP 2026
- Abuse Resistant Traceability with Minimal Trust for Encrypted Messaging SystemsZhongming Wang, Tao Xiang, Xiaoguo Li, Guomin Yang et al.NDSS 2026
Builds on35
- MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious TransferMarcel Keller, Emmanuela Orsini, Peter SchollCCS 2016 · 487 citations
- Function Secret Sharing: Improvements and ExtensionsElette Boyle, Niv Gilboa, Yuval IshaiCCS 2016 · 404 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- PIR with Compressed Queries and Amortized Query ProcessingSebastian Angel, Hao Chen, Kim Laine, Srinath T. V. SettyS&P 2018 · 353 citations
- Fast Multiparty Threshold ECDSA with Fast Trustless SetupRosario Gennaro, Steven GoldfederCCS 2018 · 264 citations
Related papers
- MPCAuth: Multi-factor Authentication for Distributed-trust SystemsSijun Tan, Weikeng Chen, Ryan Deng, Raluca Ada PopaS&P 2023
- Avocado: A Secure In-Memory Distributed Storage SystemMaurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Do Le Quoc et al.USENIX ATC 2021 · 39 citations
- CDN-on-Demand: An affordable DDoS Defense via Untrusted CloudsYossi Gilad, Amir Herzberg, Michael Sudkovitch, Michael GobermanNDSS 2016 · 59 citations
- SHORTSTACK: Distributed, Fault-tolerant, Oblivious Data AccessMidhul Vuppalapati, Kushal Babel, Anurag Khandelwal, Rachit AgarwalOSDI 2022 · 13 citations
- Boomerang: Metadata-Private Messaging under Hardware TrustPeipei Jiang, Qian Wang, Jianhao Cheng, Cong Wang et al.NSDI 2023 · 13 citations
