DiStefano: Decentralized Infrastructure for Sharing Trusted Encrypted Facts and Nothing More
Sofía Celi, Alex Davidson, Hamed Haddadi, Gonçalo Pestana, Joe Rowell
Abstract
—We design DiStefano : an efficient, maliciously-secure framework for generating private commitments over TLS-encrypted web traffic, for verification by a designated third-party. DiStefano provides many improvements over previous TLS commitment systems, including: a modular protocol specific to TLS 1.3, support for arbitrary verifiable claims over encrypted data, client browsing history privacy amongst pre-approved TLS servers, and various optimisations to ensure fast online performance of the TLS 1.3 session. We build a permissive open-source implementation of DiStefano integrated into the BoringSSL cryptographic library (used by Chromium-based Internet browsers). We show that DiStefano is practical in both LAN and WAN settings for committing to facts in arbitrary TLS traffic, requiring < 1 s and ≤ 80 KiB to execute the complete online phase of the protocol.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c81c903c-dd48-4152-a397-81be903200c9Cited by top-tier papers3
- NOPE: Strengthening domain authentication with succinct proofsZachary DeStefano, Jeff J. Ma, Joseph Bonneau, Michael WalfishSOSP 2024 · 2 citations
- Arke: Scalable and Byzantine Fault Tolerant Privacy-Preserving Contact DiscoveryNicolas Mohnblatt, Alberto Sonnino, Kobi Gurkan, Philipp JovanovicCCS 2024 · 2 citations
- ACTS: Attestations of Contents in TLS SessionsPierpaolo Della Monica, Ivan Visconti, Andrea Vitaletti, Marco ZecchiniNDSS 2026 · 1 citation
Builds on24
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels et al.CCS 2016 · 668 citations
- MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious TransferMarcel Keller, Emmanuela Orsini, Peter SchollCCS 2016 · 487 citations
- Fast Multiparty Threshold ECDSA with Fast Trustless SetupRosario Gennaro, Steven GoldfederCCS 2018 · 264 citations
- Authenticated Garbling and Efficient Maliciously Secure Two-Party ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 212 citations
Related papers
- TLS-N: Non-repudiation over TLS Enablign Ubiquitous Content SigningHubert Ritzdorf, Karl Wüst, Arthur Gervais, Guillaume Felley et al.NDSS 2018 · 32 citations
- Quantifying the Security Cost of Migrating Protocols to PracticeChristopher Patton, Thomas ShrimptonCRYPTO 2020 · 2 citations
- Verifying Indistinguishability of Privacy-Preserving ProtocolsKirby Linvill, Gowtham Kaki, Eric WustrowOOPSLA 2023 · 2 citations
- Simple High-Level Code for Cryptographic Arithmetic - With Proofs, Without CompromisesAndres Erbsen, Jade Philipoom, Jason Gross, Robert Sloan et al.S&P 2019 · 147 citations
- DECO: Liberating Web Data Using Decentralized Oracles for TLSFan Zhang, Deepak Maram, Harjasleen Malvai, Steven Goldfeder et al.CCS 2020 · 110 citations
