Tandem: Securing Keys by Using a Central Server While Preserving Privacy

by   Wouter Lueks, et al.

Users' devices, e.g., smartphones or laptops, are typically incapable of securely storing and processing cryptographic keys. We present Tandem, a novel set of protocols for securing cryptographic keys with support from a central server. Tandem uses one-time-use key-share tokens to, unlike traditional threshold-cryptographic solutions, preserve users' privacy with respect to a malicious central server. Additionally, Tandem enables users to block their keys if they lose their shares, and it enables the server to limit how often an adversary can use an unblocked key. We prove Tandem's security and privacy properties, and we empirically show that it causes little overhead using a proof of concept implementation. To illustrate Tandem's advantages we use it to secure attribute-based credentials keys using a central server without hurting the privacy properties provided by the credential system.



