How to (Legally) Keep Secrets from Mobile Operators

  • Ghada Arfaoui
  • , Olivier Blazy
  • , Xavier Bultel
  • , Pierre Alain Fouque
  • , Thibaut Jacques
  • , Adina Nedelcu
  • , Cristina Onete

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Secure-channel establishment allows two endpoints to communicate confidentially and authentically. Since they hide all data sent across them, good or bad, secure channels are often subject to mass surveillance in the name of (inter)national security. Some protocols are constructed to allow easy data interception. Others are designed to preserve data privacy and are either subverted or prohibited to use without trapdoors. We introduce LIKE, a primitive that provides secure-channel establishment with an exceptional, session-specific opening mechanism. Designed for mobile communications, where an operator forwards messages between the endpoints, it can also be used in other settings. LIKE allows Alice and Bob to establish a secure channel with respect to n authorities. If the authorities all agree on the need for interception, they can ensure that the session key is retrieved. As long as at least one honest authority prohibits interception, the key remains secure; moreover LIKE is versatile with respect to who learns the key. Furthermore, we guarantee non-frameability: nobody can falsely incriminate a user of taking part in a conversation; and honest-operator: if the operator accepts a transcript as valid, then the key retrieved by the authorities is the key that Alice and Bob should compute. Experimental results show that our protocol can be efficiently implemented.

Original languageEnglish
Title of host publicationComputer Security – ESORICS 2021 - 26th European Symposium on Research in Computer Security, Proceedings
EditorsElisa Bertino, Haya Shulman, Michael Waidner
PublisherSpringer Science and Business Media Deutschland GmbH
Pages23-43
Number of pages21
ISBN (Print)9783030884178
DOIs
Publication statusPublished - 1 Jan 2021
Externally publishedYes
Event26th European Symposium on Research in Computer Security, ESORICS 2021 - Virtual, Online
Duration: 4 Oct 20218 Oct 2021

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12972 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference26th European Symposium on Research in Computer Security, ESORICS 2021
CityVirtual, Online
Period4/10/218/10/21

Fingerprint

Dive into the research topics of 'How to (Legally) Keep Secrets from Mobile Operators'. Together they form a unique fingerprint.

Cite this