USENIX Security2024Top-tier venue
OPTIKS: An Optimized Key Transparency System
Julia Len, Melissa Chase, Esha Ghosh, Kim Laine, Radames Cruz Moreno
Abstract
Key Transparency (KT) refers to a public key distribution system with transparency mechanisms proving its correct operation, i.e., proving that it reports consistent values for each user's public key. While prior work on KT systems have offered new designs to tackle this problem, relatively little attention has been paid on the issue of scalability. Indeed, it is not straightforward to actually build a scalable and practical KT system from existing constructions, which may be too complex, inefficient, or non-resilient against machine failures. In this paper, we present OPTIKS, a full featured and optimized KT system that focuses on scalability. Our system is simpler and more performant than prior work, supporting smaller storage overhead while still meeting strong notions of security and privacy. Our design also incorporates a crash-tolerant and scalable server architecture, which we demonstrate by presenting extensive benchmarks. Finally, we address several real-world problems in deploying KT systems that have received limited attention in prior work, including account decommissioning and user-to-device mapping.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f4e1945d-e04f-456d-8790-01c879b492bcCited by top-tier papers6
- TACITA: Threshold Aggregation without Client InteractionVarun Madathil, Arthur Lazzaretti, Zeyu Liu, Charalampos PapamanthouCCS 2026 · 2 citations
- Transparent Dictionaries from Polynomial CommitmentsHossein Hafezi, Alireza Shirzad, Benedikt Bünz, Joseph BonneauUSENIX Security 2026 · 1 citation
- Pirateship: Append-Only Ledgers for (Mostly) Trusted Execution EnvironmentsShubham Mishra, João Gonçalves, Chawinphat Tankuranand, Natacha Crooks et al.SOSP 2026
- 3PaaS: Privacy-Preserving Post-Compromise Security as a ServiceCas Cremers, Abhinav Nakarmi, Aleksi Peltonen, Eyal RonenCCS 2026
- HarborMaster: Rollback Detection for Trusted Distributed ComputingShubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen et al.VLDB 2026
Builds on7
- SEEMless: Secure End-to-End Encrypted Messaging with less</> TrustMelissa Chase, Apoorvaa Deshpande, Esha Ghosh, Harjasleen MalvaiCCS 2019 · 69 citations
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang et al.S&P 2021 · 51 citations
- VeRSA: Verifiable Registries with Efficient Client Audits from RSA Authenticated DictionariesNirvan Tyagi, Ben Fisch, Andrew Zitek, Joseph Bonneau et al.CCS 2022 · 14 citations
- ELEKTRA: Efficient Lightweight multi-dEvice Key TRAnsparencyJulia Len, Melissa Chase, Esha Ghosh, Daniel Jost et al.CCS 2023 · 4 citations
- Labeled PSI from Homomorphic Encryption with Reduced Computation and CommunicationKelong Cong, Radames Cruz Moreno, Mariana Botelho da Gama, Wei Dai et al.CCS 2021 · 3 citations
Related papers
- Parakeet: Practical Key Transparency for End-to-End Encrypted MessagingHarjasleen Malvai, Lefteris Kokoris-Kogias, Alberto Sonnino, Esha Ghosh et al.NDSS 2023
- Updatable Oblivious Key Management for Storage SystemsStanislaw Jarecki, Hugo Krawczyk, Jason K. ReschCCS 2019 · 52 citations
- TAP: Transparent and Privacy-Preserving Data ServicesDaniël Reijsbergen, Aung Maw, Zheng Yang, Tien Tuan Anh Dinh et al.USENIX Security 2023
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 2 citations
- CTng: Secure Certificate and Revocation TransparencyJie Kong, James Damon, Hemi Leibowitz, Ewa Syta et al.NDSS 2026 · 5 citations
