Privacy-preserving audit mechanisms for multi-party protocols

Cuvelier, Édouard
(2015)

Files

theseVersionElectronique13112015.pdf
  • Open Access
  • Adobe PDF
  • 1.31 MB

Details

Authors
  • Cuvelier, ÉdouardUCLouvain
    author
Supervisors
Pereira, Olivier
Abstract
This thesis sets as goal the study and development of cryptographic multi-party protocols offering the properties of verifiability and privacy. The verifiability property guarantees the protocols participants and/or observers that the result of the execution of the protocol is exactly what is expected from a honest execution of the protocol. On the other hand, the privacy property ensures the participants that their private information is not leaked by executing the protocol. The thesis targets real-world applications as well as any multi-party function. The first part of the work focus on cryptographic voting systems. In this case, the function to evaluate is rather simple -- e.g. a sum of yes/no votes -- and, we show how we conciliate the verifiability with the privacy to obtain a cryptographic voting system that offers a perfectly private audit trail of its execution. A perfectly private audit trail means that it contains no information about the voters' votes whatsoever. In addition, the trail computationally guarantees the observers that the tally of the votes is correct. Next, we extend our study to encompass more complex functions. We work on combinatorial problems such as graph problems. In this part, following the traditional approach of secure multi-party computation, we investigate potential sources of privacy leakages that appear when turning the unsecured version of an algorithm into its secure version. We propose solutions to prevent these privacy leakages through algorithms for securely sorting shared lists and securely computing the shortest path and the maximum flow in shared graphs. In the last part of the thesis, we follow a different approach than the traditional secure multi-party computation one. In our approach, we rely on a third party (worker) that is entrusted with the privacy of the protocol participants' inputs. We show that several important gains can be made in this setting. We propose a generic protocol that can be used to evaluate any multi-party function while offering a perfectly private audit trail of its computation. This protocol is mainly non-interactive and offers the worker the possibility to use his own algorithms. Finally, the solutions obtained in this thesis have been implemented. The secure multi-party protocols are available in an online prototype that can be used as such or to develop any desired new multi-party application that offers perfect privacy and computational verifiability.
Affiliations

Citations

Cuvelier, É. (2015). Privacy-preserving audit mechanisms for multi-party protocols. https://hdl.handle.net/2078.5/190026