Secret Key Recovery in a Global-Scale End-to-End Encryption System
Graeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman, Raluca Ada Popa
摘要
End-to-end encrypted messaging applications ensure that an attacker cannot read a user's message history without their decryption keys. While this provides strong privacy, it creates a usability problem: if a user loses their devices and cannot access their decryption keys, they can no longer access their message history. To solve this usability problem, users should be able to back up their decryption keys with the messaging provider. For privacy, the provider should not have access to users' decryption keys. To solve this problem, we present Secure Value Recovery 3 (SVR3), a secret key recovery system that distributes trust across different types of hardware enclaves run by different cloud providers in order to protect users' decryption keys. SVR3 is the first deployed secret key recovery system to split trust across heterogeneous enclaves managed by different cloud providers: this design ensures that a single type of enclave does not become a central point of attack. SVR3 protects decryption keys via rollback protection and fault tolerance techniques tailored to the enclaves' security guarantees. SVR3 costs $0.0025/user/year and takes 365ms for a user to recover their key, which is a rare operation. A part of SVR3 has been rolled out to millions of real users in a deployment with capacity for over 500 million users, demonstrating the ability to operate at scale.
In this paper, we contribute Secure Value Recovery 3 1 , a PIN-based secret key recovery system that prevents any one type of enclave or cloud provider from becoming a central point of attack. Our security properties are informed by the observation that many vulnerabilities are quickly patched, and so it is challenging for an attacker to find vulnerabilities simultaneously on different enclave architectures. SVR3 proposes a layered architecture, illustrated in Figure 1, consisting of a tailored cryptographic multi-server key recovery protocol that distributes trust across three different enclaves from three distinct hardware vendors on three major clouds: Intel SGX in Microsoft Azure, AMD SEV-SNP in Google Cloud, and Nitro in AWS. SVR3 ensures that even if an attacker simultaneously compromises two of these enclave types and the respective clouds, the attacker cannot reconstruct the user's secrets due to the cryptographic protocol. The attacker needs to simultaneously compromise the security of all of the clouds and all of the enclave types to reach user secrets.
We implemented SVR3 as a production-ready system embedded in Signal Messenger [85], an end-to-end encrypted messaging application with tens of millions of users. We have already deployed an initial version of SVR3's implementation to millions of users globally, and the fully featured system is in the process of deployment at the time of publication. A thirdparty auditor, NCC Group, audited the deployment of Signal's SVR2, a predecessor system currently in production and using SVR3's consensus protocol on a single trust domain. SVR3 is
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks 等SIGMOD 2026 · 被引用 6 次
- Ambulance: Saving BFT through RacingNeil Giridharan, Shubham Mishra, Lorenzo Alvisi, Natacha Crooks 等OSDI 2026 · 被引用 1 次
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
- Transparent Attested DNS for Confidential Computing ServicesAntoine Delignat-Lavaud, Cédric Fournet, Kapil Vaswani, Manuel Costa 等USENIX Security 2025
- Pirateship: Append-Only Ledgers for (Mostly) Trusted Execution EnvironmentsShubham Mishra, João Gonçalves, Chawinphat Tankuranand, Natacha Crooks 等SOSP 2026
它引用的顶会 Paper28
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta 等USENIX Security 2016 · 被引用 594 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
相关 Paper
- Boomerang: Metadata-Private Messaging under Hardware TrustPeipei Jiang, Qian Wang, Jianhao Cheng, Cong Wang 等NSDI 2023 · 被引用 13 次
- SafetyPin: Encrypted Backups with Human-Memorable SecretsEmma Dauterman, Henry Corrigan-Gibbs, David MazièresOSDI 2020 · 被引用 22 次
- CHORUS: Secret Recovery with Ephemeral Client CommitteesDeevashwer Rathee, Emma Dauterman, Allison Li, Raluca Ada PopaS&P 2026 · 被引用 1 次
- SEEMless: Secure End-to-End Encrypted Messaging with less</> TrustMelissa Chase, Apoorvaa Deshpande, Esha Ghosh, Harjasleen MalvaiCCS 2019 · 被引用 69 次
- Oblix: An Efficient Oblivious Search IndexPratyush Mishra, Rishabh Poddar, Jerry Chen, Alessandro Chiesa 等S&P 2018 · 被引用 200 次
