DiStefano: Decentralized Infrastructure for Sharing Trusted Encrypted Facts and Nothing More

Sofia Celi

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Secure Protocols

Overview

In an era increasingly concerned with data privacy and the pervasive collection of personal information, the DiStefano protocol emerges as a pivotal advancement in enabling privacy-preserving interactions online. Presented by Sofia Celi at the NDSS Symposium, this work introduces a novel decentralized infrastructure designed for sharing trusted, encrypted facts without revealing the underlying sensitive data. The core innovation lies in its ability to generate cryptographic commitments over TLS 1.3 encrypted data, which can then be used to construct zero-knowledge proofs (ZKPs) about specific attributes of that data.

Watch on YouTube · Slides

Key moments

  1. 0:40 Example: proving age over 18 without revealing identity
  2. 2:00 Problem: Proving JSON field over TLS 1.3 securely
  3. 3:00 Introducing Designated Commitment TLS (DCTLS) protocols
  4. 3:50 Limitations of existing DCTLS protocols and motivation for DiStefano
  5. 5:20 DiStefano's core idea: Secretly sharing TLS 1.3 session keys
  6. 5:50 Details: Secret sharing key material in handshake phase

DiStefano: Decentralized Infrastructure for Sharing Trusted Encrypted Facts and Nothing More

Speakers: Sofia Celi

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=HdYbhQrX8Q8

Overview

In an era increasingly concerned with data privacy and the pervasive collection of personal information, the DiStefano protocol emerges as a pivotal advancement in enabling privacy-preserving interactions online. Presented by Sofia Celi at the NDSS Symposium, this work introduces a novel decentralized infrastructure designed for sharing trusted, encrypted facts without revealing the underlying sensitive data. The core innovation lies in its ability to generate cryptographic commitments over TLS 1.3 encrypted data, which can then be used to construct zero-knowledge proofs (ZKPs) about specific attributes of that data.

DiStefano addresses a critical gap in existing protocols: the lack of robust, privacy-preserving mechanisms for proving facts derived from encrypted communications. Leveraging the ubiquitous Transport Layer Security (TLS) protocol, specifically its most secure iteration, TLS 1.3, DiStefano allows users to obtain verifiable credentials from web services (e.g., a bank) and subsequently prove specific facts about these credentials to other services without re-exposing sensitive identity documents or revealing their browsing history. This capability holds profound implications for online identity verification, regulatory compliance, and the broader landscape of digital privacy, offering a pathway towards a more secure and user-centric internet experience.

Background

▶ Watch: Example: proving age over 18 without revealing identity (0:40)

The concept of proving specific attributes of data without disclosing the data itself has long been a holy grail in cryptography and privacy research. Traditional methods often involve directly presenting sensitive documents or relying on centralized identity providers, both of which introduce significant privacy risks and single points of failure. The challenge intensifies when this data is transmitted over encrypted channels, as the encryption itself makes it difficult to prove anything about the content to a third party without first decrypting it, thereby compromising privacy.

Prior research has explored three-party handshake protocols, often referred to as Client-Key-TLS (CKTLS) or, as defined in this paper, Designated Commitment TLS (DCTLS) protocols. These protocols aim to allow a client, in conjunction with a trusted third-party verifier, to commit to data exchanged during a TLS session. Examples include DecoTLS, NotaryCryer, Gobbled, Proof, and Janus. While these systems laid foundational groundwork, they suffered from several critical limitations that hindered their practical adoption and widespread applicability.

Specifically, existing DCTLS protocols often lacked explicit and detailed support for TLS 1.3, the latest and most secure version of the protocol, which is non-trivial to migrate from earlier versions like TLS 1.2 due to significant architectural changes. Furthermore, many prior works were deficient in formal security analyses, raised efficiency concerns due to complex cryptographic operations, introduced privacy violations by potentially revealing client browsing history to the verifier, and lacked open-source implementations for community review and development. DiStefano was conceived to directly address these accumulated shortcomings, providing a comprehensive solution that is secure, efficient, privacy-preserving, and compatible with modern internet standards.

Key Findings

▶ Watch: Introducing Designated Commitment TLS (DCTLS) protocols (3:00)

The DiStefano protocol represents a significant leap forward in the realm of privacy-preserving attested data. Its key findings and contributions can be summarized as follows:

  1. First TLS 1.3-Compatible Commitment System: DiStefano is presented as the first complex system to enable the generation of cryptographic commitments over AES-GCM encrypted data transmitted specifically over a TLS 1.3 connection. This is a crucial distinction, as migrating such protocols to TLS 1.3 is non-trivial due to its enhanced security features and architectural differences, including the encryption of most handshake messages.
  1. Addressing the AES-GCM Key Committing Attack: A critical discovery was the vulnerability of standard AES-GCM to a key committing attack in the context of DCTLS protocols. This attack allows a client to find the same ciphertext for different messages and different keys, effectively breaking the commitment property. DiStefano introduces a novel modification to AES-GCM that ensures commitments are always provided for both the specific message and the keys used in the encryption, thereby preventing this attack.
  1. Enhanced Client Privacy for Server Authentication: DiStefano introduces a ring signature zero-knowledge proof mechanism during the handshake phase. This allows the client to attest to the verifier that they are communicating with a legitimate server from a publicly known set, without revealing the specific identity of the server or the client's browsing history to the verifier. This is a significant improvement over simply forwarding server certificates, which would constitute a privacy violation.
  1. Formal Security Analysis and Open-Source Implementation: Unlike many prior works, DiStefano is designed with a strong emphasis on formal security analysis. The project also provides an open-source C++ implementation, integrated into BoringSSL, comprising approximately 14,000 lines of code. This commitment to transparency and verifiable security significantly enhances trust and allows for community scrutiny and further development.
  1. Practical Efficiency: Despite its cryptographic complexity, DiStefano demonstrates practical efficiency. Performance measurements indicate that the handshake phase completes in less than one second, which is within acceptable bounds for typical TLS 1.3 implementations. Furthermore, the online phase requires sending less than or equal to 80 KB of data, demonstrating network efficiency. This is partly achieved through significant optimizations in the pre-processing phase of the underlying multi-party computation (MPC) protocols.

These findings collectively establish DiStefano as a robust and practical solution for generating verifiable commitments over encrypted web traffic, paving the way for a new generation of privacy-preserving online services and credentials.

Technical Deep Dive

▶ Watch: Limitations of existing DCTLS protocols and motivation for DiStefano (3:50)

DiStefano is built upon the framework of Designated Commitment TLS (DCTLS) protocols, which extend the standard TLS handshake to include a third-party verifier. These protocols operate in three concurrent phases: a handshake phase, a query phase, and a commit phase. The fundamental goal is to enable a client to generate commitments to specific data transmitted over a TLS connection, with the assistance of a verifier, so that these commitments can later be used to generate zero-knowledge proofs.

The protocol's architecture begins by adapting TLS 1.3, which itself is structured into a handshake layer (for key establishment and server authentication) and a record layer (for application data encryption). A core challenge in integrating a third-party verifier into TLS 1.3 is to ensure that the verifier can commit to the data without gaining full access to the encryption keys or compromising client privacy. DiStefano achieves this through secret sharing of session keys.

In the handshake phase, the client and the verifier jointly compute and hold additive shares of the session key material. All cryptographic operations necessary for deriving the keys used to encrypt handshake messages and later record layer messages are performed in a secret-shared pool. This means neither the client nor the verifier ever possesses the complete session key on their own, preserving confidentiality. However, at specific points, the verifier reveals its share of the key material to the client, enabling the client to decrypt messages received from the server. This mechanism allows the verifier to commit to the encrypted messages as they are processed, without ever seeing the plaintext content directly.

A significant challenge in the handshake phase is server authentication. In standard TLS, the client authenticates the server using its certificate. If the client were to simply forward the server's certificate to the verifier, it would reveal the identity of the server and, over time, the client's browsing history, violating privacy. DiStefano circumvents this by employing a ring signature zero-knowledge proof. This ZKP allows the client to prove to the verifier that it is indeed communicating with a legitimate server from a pre-defined set of publicly known servers, without disclosing which specific server it is. This ensures the verifier's assurance while upholding client privacy.

Another critical technical innovation addresses a vulnerability in the widely used AES-GCM (Galois/Counter Mode) cipher suite, which is standard in TLS 1.3. In a multi-party setting where commitments are desired, standard AES-GCM is susceptible to a key committing attack. This attack allows a malicious client to craft different messages and use different keys that result in the same ciphertext. This breaks the commitment property, as the verifier could not be certain which original message or key was used. DiStefano resolves this by modifying the AES-GCM algorithm itself. The modification ensures that the encryption process inherently commits to both the plaintext message and the specific keys used for encryption. This prevents the client from launching the key committing attack, thereby guaranteeing the integrity of the commitments.

Following the handshake, the protocol proceeds to the record layer, which involves the query and commit phases. Here, the client queries the server for specific data, and the server responds. Similar to the handshake phase, messages at the record layer are received by the client, forwarded to the verifier for commitment (using the modified AES-GCM and secret-shared keys), and only after commitment does the verifier reveal its key share, allowing the client to decrypt the messages. This continuous commitment process ensures that all relevant data exchanged during the session can be later used for ZKP generation.

To ensure practical performance, DiStefano incorporates significant optimizations, particularly in the pre-processing phase of the underlying MPC computations. Generating the additive shares and performing complex cryptographic operations can be computationally intensive. By heavily modifying the pre-processing phase, DiStefano offloads the majority of these computations to an offline stage. This means that when the actual TLS handshake is initiated, the required key shares are already pre-computed, significantly reducing the online computational bottleneck and contributing to the observed sub-second handshake times.

The entire system is implemented in C++ and integrated into BoringSSL, a widely used fork of OpenSSL, demonstrating its readiness for integration into real-world applications. The implementation comprises approximately 14,000 lines of code.

Demo / Proof of Concept

▶ Watch: DiStefano's core idea: Secretly sharing TLS 1.3 session keys (5:20)

While the presentation did not feature a live, interactive demonstration of the DiStefano protocol in action, the authors confirm the existence of a working, open-source implementation. This implementation, written in C++ and integrated into BoringSSL, serves as the proof of concept for the proposed architecture. The team has performed extensive performance measurements, both in LAN and WAN settings, to validate the protocol's efficiency and practicality.

Key performance metrics presented include:

  • Handshake time: Less than one second. This is a crucial achievement, as it keeps the added overhead of the DCTLS protocol within the acceptable latency for a typical TLS 1.3 handshake.
  • Online phase data transmission: Less than or equal to 80 KB. This indicates a lean network footprint for the additional cryptographic exchanges required by DiStefano, minimizing bandwidth consumption.

The focus of this paper and its associated implementation is on establishing the ability to generate cryptographic commitments over TLS 1.3 encrypted data. The creation of complex zero-knowledge proofs (e.g., proving a field exists in a JSON document, is an integer, and meets a specific condition like "over 18") based on these commitments is highlighted as future work. However, the successful implementation and performance evaluation of the commitment mechanism itself validate DiStefano's foundational premise and its potential to enable such ZKP applications. The availability of the open-source code further allows other researchers and developers to experiment with and build upon this core capability.

Defensive Implications

▶ Watch: Details: Secret sharing key material in handshake phase (5:50)

DiStefano offers significant defensive implications for individuals and organizations seeking to enhance privacy, reduce data exposure, and comply with increasingly stringent data protection regulations.

  1. Privacy-Preserving Credentials and Identity Verification: The most direct defensive implication is the ability to obtain and utilize privacy-preserving credentials. Instead of repeatedly sharing sensitive documents (like a passport or driver's license) to prove attributes (e.g., age, residency), users can leverage DiStefano to generate a ZKP based on a one-time interaction with a trusted issuer (e.g., a bank). This drastically reduces the surface area for personal data exposure, mitigating risks associated with data breaches and identity theft. Organizations that require attribute verification can adopt this model to reduce their liability by not storing sensitive personal information, but rather verifying a cryptographic proof.
  1. Reduced Data Collection and Storage: For service providers, DiStefano presents an opportunity to minimize the collection and storage of sensitive user data. If an organization only needs to verify a specific fact (e.g., "this user is over 18"), rather than storing the user's full date of birth or identity document, they can accept a ZKP. This aligns with data minimization principles and reduces the regulatory burden and operational costs associated with handling sensitive information, thus strengthening their defensive posture against data breaches.
  1. Enhanced Trust in Online Interactions: By providing a verifiable commitment to encrypted data, DiStefano increases the overall trustworthiness of online interactions. Users can have greater assurance that the facts they are presenting are genuinely derived from a trusted source and have not been tampered with. This can combat fraud and misrepresentation in online services.
  1. Secure and Private Auditing/Compliance: In regulated industries, the ability to prove facts about encrypted communications without revealing the underlying content could revolutionize auditing and compliance. Regulators could verify that certain data exists or adheres to specific formats (e.g., financial transaction records) through ZKPs, without needing access to the raw, sensitive data. This would protect both the privacy of individuals and the proprietary information of organizations.
  1. Future-Proofing Against Evolving Threats: The protocol's explicit support for TLS 1.3 ensures it benefits from the strongest cryptographic protections available in common web communication. Its design to counter specific attacks like the AES-GCM key committing attack demonstrates a proactive approach to security, making it resilient against sophisticated cryptographic manipulations. Adopting such a protocol helps organizations future-proof their security architecture against evolving cyber threats and privacy concerns.

In essence, DiStefano empowers both individuals and organizations to operate with a "need-to-know" approach to data, where only the necessary facts are revealed, rather than the entire dataset. This fundamental shift significantly strengthens the defensive capabilities of all parties involved in online transactions and interactions.

Key Takeaways

  • Privacy-Preserving Proofs: DiStefano enables the creation of cryptographic commitments over TLS 1.3 encrypted data, allowing users to generate zero-knowledge proofs (ZKPs) about specific facts without revealing the underlying sensitive information.
  • TLS 1.3 Compatibility: It is the first complex system to provide explicit and detailed support for generating commitments over TLS 1.3, addressing a critical limitation of previous three-party handshake protocols.
  • Enhanced AES-GCM Security: The protocol modifies the standard AES-GCM cipher to prevent a "key committing attack," ensuring that commitments are robustly tied to both the message and the encryption keys.
  • Client Privacy in Server Authentication: DiStefano uses a ring signature zero-knowledge proof to allow the client to prove server authenticity to the verifier without disclosing the specific server's identity or the client's browsing history.
  • Practical Efficiency: Despite its advanced cryptographic techniques, DiStefano achieves a handshake time of less than one second and an online data transmission of less than 80 KB, making it practical for real-world deployment.
  • Open-Source and Auditable: The protocol provides an open-source C++ implementation integrated into BoringSSL (~14,000 lines of code), fostering transparency, community review, and further development.

About the Speaker(s)

The paper "DiStefano: Decentralized Infrastructure for Sharing Trusted Encrypted Facts and Nothing More" was presented by Sofia Celi at the NDSS Symposium. Sofia Celi is credited as the presenter of this significant work, which was developed in collaboration with Alex Davidson, Hamemed Hadadi, Gonalo Pastana, and Jo. While the transcript does not provide further biographical details, her role in presenting and co-authoring this research highlights her expertise and contributions to the fields of cryptography, privacy-preserving technologies, and secure decentralized systems.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, original cryptographic systems work that earns its complexity. DiStefano ships a real TLS 1.3-compatible DCTLS protocol with a working BoringSSL implementation, identifies and patches a concrete AES-GCM key-committing vulnerability, and uses ring-signature ZKPs to solve a privacy problem that prior three-party handshake schemes quietly ignored. The ZKP layer over commitments being punted to future work is a genuine limitation, but the foundation laid here is non-trivial.

Heather Calloway (CISO) — WEAK

Technically credible cryptography research that solves a real problem — privacy-preserving attribute proofs over TLS 1.3 — but it never crosses the bridge into institutional relevance. The defensive implications section reads like a press release, not a deployment guide, and no one in a CISO seat leaves knowing what to actually do with this.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025