CONIKS: Bringing Key Transparency to End Users

Marcela S. Melara, Aaron Blankstein, Joseph Bonneau, Edward W. Felten, Michael J. Freedman · 2014

We present CONIKS, an end-user key verification ser-vice capable of integration in end-to-end encrypted com-munication systems. CONIKS builds on transparency log proposals for web server certificates but solves sev-eral new challenges specific to key verification for end users. CONIKS obviates the need for global third-party monitors and enables users to efficiently monitor their own key bindings for consistency, downloading less than 20 kB per day to do so even for a provider with billions of users. CONIKS users and providers can collectively audit providers for non-equivocation, and this requires downloading a constant 2.5 kB per provider per day. Ad-ditionally, CONIKS preserves the level of privacy offered by today’s major communication services, hiding the list of usernames present and even allowing providers to con-ceal the total number of users in the system. 1

Read the paper · More papers on PaperTik