Tandem: Securing Keys by Using a Central Server While Preserving Privacy
Wouter Lueks, Brinda Hampiholi, Greg Alpár, Carmela Troncoso · Proceedings on Privacy Enhancing Technologies · 2020
Abstract Users’ devices, e.g., smartphones or laptops, are typically incapable of securely storing and processing cryptographic keys.We present Tandem, a novel set of protocols for securing cryptographic keys with support from a central server. Tandemusesone-time-use key-share tokensto preserve users’ privacy with respect to a malicious central server. Additionally, Tandemenables users to block their keys if they lose their device, and it enables the server to limit how often an adversary can use an unblocked key. We prove Tandem’s security and privacy properties, apply Tandemto attributebased credentials, and implement a Tandemproof of concept to show that it causes little overhead.