Skip to main navigation Skip to search Skip to main content

DIDO: Data Provenance from Restricted TLS 1.3 Websites

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

Abstract

Public data can be authenticated by obtaining from a trustworthy website with TLS. Private data, such as user profile, are usually restricted from public access. If a user wants to authenticate his private data (e.g., address) provided by a restricted website (e.g., user profile page of a utility company website) to a verifier, he cannot simply give his username and password to the verifier. DECO (CCS 2020) provides a solution for liberating these data without introducing undesirable trust assumption, nor requiring server-side modification for TLS 1.2.

In this paper, we propose an optimized solution for TLS 1.3 websites. We tackle a number of open problems, including the support of X25519 key exchange in TLS 1.3, the design of round-optimal three-party key exchange, the architecture of two-party computation of TLS 1.3 key scheduling, and circuit design optimized for two-party computation. We test our implementation with real world website and show that our optimization is necessary to avoid timeout in TLS handshake.
Original languageEnglish
Title of host publicationInformation Security Practice and Experience - 18th International Conference, ISPEC 2023 Copenhagen, Denmark, August 24–25, 2023 Proceedings
EditorsWeizhi Meng, Zheng Yan, Vincenzo Piuri
Place of PublicationSingapore Singapore
PublisherSpringer
Pages154-169
Number of pages16
ISBN (Electronic)9789819970322
ISBN (Print)9789819970315
DOIs
Publication statusPublished - 2023
Externally publishedYes
EventInformation Security Practice and Experience Conference 2023 - Copenhagen, Denmark
Duration: 24 Aug 202325 Aug 2024
Conference number: 18th
https://link.springer.com/book/10.1007/978-981-99-7032-2 (Proceedings)
https://ispec2023.compute.dtu.dk/ (Website)

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume14341

Conference

ConferenceInformation Security Practice and Experience Conference 2023
Abbreviated titleISPEC 2023
Country/TerritoryDenmark
CityCopenhagen
Period24/08/2325/08/24
Internet address

Cite this