Design & Evaluation of an Accessible High-Level Language for Advanced Cryptography

Ulla Aeschbacher · Repository for Publications and Research Data (ETH Zurich) · 2020

More and more private data is being used by companies to offer personally tailored services to users.These services access a lot of private data to provide users with useful utilities.Protecting private data is becoming more important to a lot of people but at the same time, they want to still use these services.Until recently, a user either had to entrust the company with their unencrypted private data or else could not reap the offered benefits.This is bothersome not only for the user but also the company, which does not want to miss out on the user's business.Advanced cryptography concepts, most importantly Fully Homomorphic Encryption (FHE) and Secure Multi-Party Computation (SMPC), allow privacy-preserving computations, where users can benefit from offloading computation on user-encrypted data to a third party.This allows users to utilise personally tailored services while at the same time not having to give up their privacy.Unfortunately, using these concepts is currently very difficult and requires a lot of cryptographic knowledge from the user.Recent advances have been made to make specific techniques more accessible to the public, but all of them lack features or still require more cryptographic knowledge than an average user would possess.Additionally, there exists no tool that successfully combines the full functionality of both FHE and SMPC.In this thesis, we introduce Chisel, an easy to use high-level language for advanced cryptography.In contrast, most existing tools are realised as libraries or language extension, which restricts their design.Using a language allows us full freedom to design the most userfriendly, accessible and expressive solution with which the user can specify their advanced cryptography application in a natural, intuitive way.Based on findings from a preliminary study on both our ideas and existing tools, we develop a design for a domain-specific language and implement it with the help of the JetBrains Meta Programming System (MPS).To evaluate the usability of our implementation, we design a validation study that compares Chisel to two existing advanced cryptography tools by doing within-subject A/B testing.v This thesis would not exist in this form without the continuous feedback and enthusiasm from my supervisor Alexander Viand.He was always there for a meeting and our discussions were extremely helpful when I did not know how to proceed.Moreover, his reviews and his knowledge of technical writing helped to improve the readability and clarity of this thesis a lot.I would like to thank Professor Friedemann Mattern and the whole research group for enabling me to write this thesis and providing me with a workspace in the office.I was very lucky to work in such a welcoming environment and have lots of good discussions over tea or coffee breaks. My thanks go to everyone that proofread my thesis, notably David and Adrian. A big thank you goes to my parents for reviewing

Read the paper · More papers on PaperTik