DiSE: Distributed Symmetric-key Encryption
Shashank Agrawal, Payman Mohassel, Pratyay Mukherjee, Peter Rindal
Abstract
Threshold cryptography provides a mechanism for protecting secret keys by sharing them among multiple parties, who then jointly perform cryptographic operations. An attacker who corrupts upto a threshold number of parties cannot recover the secrets or violate security. Prior works in this space have mostly focused on definitions and constructions for public-key cryptography and digital signatures, and thus do not capture the security concerns and efficiency challenges of symmetric-key based applications which commonly use long-term (centralized) master keys to protect data at rest, authenticate clients on enterprise networks, and secure data and payments on IoT devices. We put forth the first formal treatment for distributed symmetrickey encryption, proposing new notions of correctness, privacy and authenticity in presence of malicious attackers. We provide strong and intuitive game-based definitions that are easy to understand and yield efficient constructions. We propose a generic construction of threshold authenticated encryption based on any distributed pseudorandom function (DPRF). When instantiated with the two different DPRF constructions proposed by Naor, Pinkas and Reingold (Eurocrypt 1999) and our enhanced versions, we obtain several efficient constructions meeting different security definitions. We implement these variants and provide extensive performance comparisons. Our most efficient instantiation uses only symmetric-key primitives and achieves a throughput of upto 1 million encryptions/decryptions per seconds, or alternatively a sub-millisecond latency with upto 18 participating parties.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c1dcea0c-1668-489e-a3ee-4331262686a3Cited by top-tier papers7
- Threshold Schnorr with Stateless Deterministic Signing from Standard AssumptionsFrançois Garillot, Yashvanth Kondi, Payman Mohassel, Valeria NikolaenkoCRYPTO 2021 · 39 citations
- i-TiRE: Incremental Timed-Release Encryption or How to use Timed-Release Encryption on Blockchains?Leemon Baird, Pratyay Mukherjee, Rohit SinhaCCS 2022 · 16 citations
- FlexiRand: Output Private (Distributed) VRFs and Application to BlockchainsAniket Kate, Easwar Vivek Mangipudi, Siva Maradana, Pratyay MukherjeeCCS 2023 · 11 citations
- Password-Protected Key Retrieval with(out) HSM ProtectionSebastian H. Faller, Tobias Handirk, Julia Hesse, Máté Horváth et al.CCS 2024 · 3 citations
- Vitārit: Paying for Threshold Services on Bitcoin and FriendsSri Aravinda Krishnan Thyagarajan, Easwar Vivek Mangipudi, Lucjan Hanzlik, Aniket Kate et al.S&P 2025
Builds on2
Related papers
- Amortized Threshold Symmetric-key EncryptionMihai Christodorescu, Sivanarayana Gaddam, Pratyay Mukherjee, Rohit SinhaCCS 2021
- Threshold Encryption with Silent SetupSanjam Garg, Dimitris Kolonelos, Guru-Vamsi Policharla, Mingyuan WangCRYPTO 2024 · 31 citations
- LaKey: Efficient Lattice-Based Distributed PRFs Enable Scalable Distributed Key ManagementMatthias Geihs, Hart MontgomeryUSENIX Security 2024 · 7 citations
- On Threshold Fully Homomorphic Encryption with Synchronized DecryptorsFrançois Colin de Verdière, Alain Passelègue, Damien StehléCCS 2026 · 2 citations
- Global-Scale Secure Multiparty ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 220 citations
