Finding Safety in Numbers with Secure Allegation Escrows
Venkat Arun, Aniket Kate, Deepak Garg, Peter Druschel, Bobby Bhattacharjee · 2020
For fear of retribution, the victim or witness of a crime may be willing to report it only if other victims of the same perpetrator also step forward.Examples include 1) identifying oneself as the victim of sexual harassment, especially by a person in a position of authority or 2) accusing an influential politician, an authoritarian government, or one's own employer of corruption.To handle such situations, legal literature has proposed the concept of an allegation escrow: a neutral third-party that collects allegations, matches them against each other, and discloses them only after reveal thresholds (in terms of number of co-allegers), pre-specified by the allegers, are reached.Until then, allegations and allegers' identities are kept confidential.An allegation escrow can be realized as a single trusted third party; however, this party must then be trusted to keep the identity of the alleger and content of the allegation private despite any threats or coercion from perpetrators.To address this problem, this paper introduces Secure Allegation Escrows (SAE, pronounced "say").A SAE is a group of parties with independent interests and motives, acting jointly as an allegation escrow.By design, SAEs provide a very strong property: No less than a majority of parties constituting a SAE can de-anonymize or disclose the content of an allegation without a sufficient number of matching allegations (even in collusion with any number of other allegers).Once a sufficient number of matching allegations exist, the joint escrow discloses the allegation and the allegers' identities.We describe how SAEs can be securely constructed using a distributed authentication protocol and a novel allegation matching and bucketing algorithm and evaluate a prototype implementation, demonstrating feasibility in practice.