Transparency Logs via Append-Only Authenticated Dictionaries
Transparency Logs via Append-Only Authenticated Dictionaries
复制标题
DOI:
10.1145/3319535.3345652
复制
发表时间:
2019-11
期刊:
影响因子:
--
通讯作者:
Alin Tomescu;Vivek Bhupatiraju;D. Papadopoulos;Charalampos Papamanthou;Nikos Triandopoulos;S. Devadas
中科院分区:
文献类型:
--
作者:
Alin Tomescu;Vivek Bhupatiraju;D. Papadopoulos;Charalampos Papamanthou;Nikos Triandopoulos;S. Devadas
Transparency logs allow users to audit a potentially malicious service, paving the way towards a more accountable Internet. For example, Certificate Transparency (CT) enables domain owners to audit Certificate Authorities (CAs) and detect impersonation attacks. Yet, to achieve their full potential, transparency logs must be bandwidth-efficient when queried by users. Specifically, everyone should be able to efficientlylook up log entries by their keyand efficiently verify that the log remainsappend-only. Unfortunately, without additional trust assumptions, current transparency logs cannot provide both small-sizedlookup proofs and small-sizedappend-only proofs. In fact, one of the proofs always requires bandwidth linear in the size of the log, making it expensive for everyone to query the log. In this paper, we address this gap with a new primitive called anappend-only authenticated dictionary (AAD). Our construction is the first to achieve (poly)logarithmic size for both proof types and helps reduce bandwidth consumption in transparency logs. This comes at the cost of increased append times and high memory usage, both of which remain to be improved to make practical deployment possible.