Papers:
Crypto 2017,
Crypto 2018,
Crypto 2019,
CCS 2019,
USENIX Security 2021,
USENIX Security 2022,
USENIX Security 2022,
Asiacrypt 2022,
Eurocrypt 2023,
Oakland 2024
Description:
We have been exploring committing authenticated encryption,
which refers to schemes for which adversaries cannot find
multiple secret keys that decrypt the same ciphertext. This
proves important in applications like message franking, a
cryptographic technique used by Facebook to
enable securely reporting of abusive end-to-end encrypted
messages. We have also explored new cryptographic
constructions for enabling message franking in anonymous
communications, providing the ability to trace the source
of a forwarded abusive message, rich governance policies such
as voting for moderators in group messaging, and more - all without sacrificing
end-to-end encryption guarantees.
This line of work discovered subtle vulnerabilities in
Facebook's message franking scheme (subsequently fixed due to
a responsible disclosure process), a whole new class of
confidentiality attacks exploiting lack of commitment called
partitioning oracle attacks, and calls by practitioners and
others to build a new generation of encryption schemes that
enjoy commitment.