{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T00:28:30Z","timestamp":1786753710549,"version":"3.56.0"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031683787","type":"print"},{"value":"9783031683794","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-68379-4_3","type":"book-chapter","created":{"date-parts":[[2024,8,15]],"date-time":"2024-08-15T16:17:23Z","timestamp":1723738643000},"page":"75-109","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Compact Key Storage"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1013-6318","authenticated-orcid":false,"given":"Yevgeniy","family":"Dodis","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6562-9665","authenticated-orcid":false,"given":"Daniel","family":"Jost","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5109-1641","authenticated-orcid":false,"given":"Antonio","family":"Marcedone","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,8,16]]},"reference":[{"key":"3_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/978-3-030-17653-2_5","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"J Alwen","year":"2019","unstructured":"Alwen, J., Coretti, S., Dodis, Y.: The double ratchet: security notions, proofs, and modularization for the signal protocol. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019. LNCS, vol. 11476, pp. 129\u2013158. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17653-2_5"},{"key":"3_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"248","DOI":"10.1007\/978-3-030-56784-2_9","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"J Alwen","year":"2020","unstructured":"Alwen, J., Coretti, S., Dodis, Y., Tselekounis, Y.: Security analysis and improvements for the IETF MLS standard for group messaging. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12170, pp. 248\u2013277. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56784-2_9"},{"key":"3_CR3","doi-asserted-by":"publisher","unstructured":"Bagherzandi, A., Jarecki, S., Saxena, N., Lu, Y.: Password-protected secret sharing. In: Chen, Y., Danezis, G., Shmatikov, V. (eds.) ACM CCS 2011, pp. 433\u2013444. ACM Press (2011). https:\/\/doi.org\/10.1145\/2046707.2046758","DOI":"10.1145\/2046707.2046758"},{"key":"3_CR4","unstructured":"Barnes, R., Beurdouche, B., , Millican, J., Omara, E., Cohn-Gordon, K., Robert, R.: The messaging layer security (MLS) protocol (draft-ietf-mls-protocol-latest). Technical report, IETF (2020). https:\/\/messaginglayersecurity.rocks\/mls-protocol\/draft-ietf-mls-protocol.html"},{"key":"3_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"516","DOI":"10.1007\/978-3-662-46447-2_23","volume-title":"Public-Key Cryptography \u2013 PKC 2015","author":"M Bellare","year":"2015","unstructured":"Bellare, M., Keelveedhi, S.: Interactive message-locked encryption and secure deduplication. In: Katz, J. (ed.) PKC 2015. LNCS, vol. 9020, pp. 516\u2013538. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46447-2_23"},{"key":"3_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"296","DOI":"10.1007\/978-3-642-38348-9_18","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2013","author":"M Bellare","year":"2013","unstructured":"Bellare, M., Keelveedhi, S., Ristenpart, T.: Message-locked encryption and secure deduplication. In: Johansson, T., Nguyen, P.Q. (eds.) EUROCRYPT 2013. LNCS, vol. 7881, pp. 296\u2013312. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38348-9_18"},{"key":"3_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"542","DOI":"10.1007\/978-3-662-49099-0_20","volume-title":"Theory of Cryptography","author":"M Bellare","year":"2016","unstructured":"Bellare, M., Stepanovs, I., Tessaro, S.: Contention in cryptoland: obfuscation, leakage and UCE. In: Kushilevitz, E., Malkin, T. (eds.) TCC 2016, Part II. LNCS, vol. 9563, pp. 542\u2013564. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-49099-0_20"},{"key":"3_CR8","unstructured":"Best, J., Hineman, W., Hetzler, S., Hunt, G., Jutla, C.S.: Secure storage with deduplication. Cryptology ePrint Archive, Paper 2022\/553 (2022). https:\/\/eprint.iacr.org\/2022\/553"},{"key":"3_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1007\/978-3-030-64840-4_19","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"D Boneh","year":"2020","unstructured":"Boneh, D., Eskandarian, S., Kim, S., Shih, M.: Improving speed and security in updatable encryption schemes. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12493, pp. 559\u2013589. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64840-4_19"},{"key":"3_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1007\/978-3-642-40041-4_23","volume-title":"Advances in Cryptology \u2013 CRYPTO 2013","author":"D Boneh","year":"2013","unstructured":"Boneh, D., Lewi, K., Montgomery, H., Raghunathan, A.: Key homomorphic PRFs and their applications. In: Canetti, R., Garay, J.A. (eds.) CRYPTO 2013, Part I. LNCS, vol. 8042, pp. 410\u2013428. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40041-4_23"},{"key":"3_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-642-42045-0_15","volume-title":"Advances in Cryptology - ASIACRYPT 2013","author":"D Boneh","year":"2013","unstructured":"Boneh, D., Waters, B.: Constrained pseudorandom functions and their applications. In: Sako, K., Sarkar, P. (eds.) ASIACRYPT 2013, Part II. LNCS, vol. 8270, pp. 280\u2013300. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-42045-0_15"},{"key":"3_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"464","DOI":"10.1007\/978-3-030-56784-2_16","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"C Boyd","year":"2020","unstructured":"Boyd, C., Davies, G.T., Gj\u00f8steen, K., Jiang, Y.: Fast and secure updatable encryption. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020, Part I. LNCS, vol. 12170, pp. 464\u2013493. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56784-2_16"},{"key":"3_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"501","DOI":"10.1007\/978-3-642-54631-0_29","volume-title":"Public-Key Cryptography \u2013 PKC 2014","author":"E Boyle","year":"2014","unstructured":"Boyle, E., Goldwasser, S., Ivan, I.: Functional signatures and pseudorandom functions. In: Krawczyk, H. (ed.) PKC 2014. LNCS, vol. 8383, pp. 501\u2013519. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-642-54631-0_29"},{"key":"3_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1007\/978-3-662-44371-2_11","volume-title":"Advances in Cryptology \u2013 CRYPTO 2014","author":"C Brzuska","year":"2014","unstructured":"Brzuska, C., Farshim, P., Mittelbach, A.: Indistinguishability obfuscation and UCEs: the case of computationally unpredictable sources. In: Garay, J.A., Gennaro, R. (eds.) CRYPTO 2014, Part I. LNCS, vol. 8616, pp. 188\u2013205. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-44371-2_11"},{"key":"3_CR15","doi-asserted-by":"publisher","unstructured":"Das, P., Hesse, J., Lehmann, A.: DPaSE: distributed password-authenticated symmetric-key encryption, or how to get many keys from one password. In: Suga, Y., Sakurai, K., Ding, X., Sako, K. (eds.) ASIACCS 22, pp. 682\u2013696. ACM Press (2022). https:\/\/doi.org\/10.1145\/3488932.3517389","DOI":"10.1145\/3488932.3517389"},{"key":"3_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-031-38551-3_11","volume-title":"Advances in Cryptology - CRYPTO 2023","author":"GT Davies","year":"2023","unstructured":"Davies, G.T., et al.: Security analysis of the WhatsApp end-to-end encrypted backup protocol. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023. LNCS, vol. 14084, pp. 330\u2013361. Springer Nature Switzerland, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38551-3_11"},{"key":"3_CR17","doi-asserted-by":"publisher","unstructured":"Dodis, Y., Jost, D., Kesavan, B., Marcedone, A.: End-to-end encrypted zoom meetings: proving security and strengthening liveness. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023, Part V. LNCS, vol. 14008, pp. 157\u2013189. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_6","DOI":"10.1007\/978-3-031-30589-4_6"},{"key":"3_CR18","doi-asserted-by":"publisher","unstructured":"Douceur, J., Adya, A., Bolosky, W., Simon, P., Theimer, M.: Reclaiming space from duplicate files in a serverless distributed file system. In: Proceedings 22nd International Conference on Distributed Computing Systems, pp. 617\u2013624 (2002). https:\/\/doi.org\/10.1109\/ICDCS.2002.1022312","DOI":"10.1109\/ICDCS.2002.1022312"},{"key":"3_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/978-3-319-63697-9_4","volume-title":"Advances in Cryptology \u2013 CRYPTO 2017","author":"A Everspaugh","year":"2017","unstructured":"Everspaugh, A., Paterson, K., Ristenpart, T., Scott, S.: Key rotation for authenticated encryption. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017, Part III. LNCS, vol. 10403, pp. 98\u2013129. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63697-9_4"},{"key":"3_CR20","doi-asserted-by":"publisher","unstructured":"Halevi, S., Harnik, D., Pinkas, B., Shulman-Peleg, A.: Proofs of ownership in remote storage systems. In: Chen, Y., Danezis, G., Shmatikov, V. (eds.) ACM CCS 2011, pp. 491\u2013500. ACM Press (2011). https:\/\/doi.org\/10.1145\/2046707.2046765","DOI":"10.1145\/2046707.2046765"},{"key":"3_CR21","doi-asserted-by":"publisher","unstructured":"Jarecki, S., Kiayias, A., Krawczyk, H., Xu, J.: Highly-efficient and composable password-protected secret sharing (or: How to protect your bitcoin wallet online). In: 2016 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 276\u2013291. IEEE Computer Society, Los Alamitos, CA, USA (2016). https:\/\/doi.org\/10.1109\/EuroSP.2016.30, https:\/\/doi.ieeecomputersociety.org\/10.1109\/EuroSP.2016.30","DOI":"10.1109\/EuroSP.2016.30"},{"key":"3_CR22","doi-asserted-by":"publisher","unstructured":"Jarecki, S., Krawczyk, H., Resch, J.K.: Updatable oblivious key management for storage systems. In: Cavallaro, L., Kinder, J., Wang, X., Katz, J. (eds.) ACM CCS 2019, pp. 379\u2013393. ACM Press (2019). https:\/\/doi.org\/10.1145\/3319535.3363196","DOI":"10.1145\/3319535.3363196"},{"key":"3_CR23","doi-asserted-by":"publisher","unstructured":"Kiayias, A., Papadopoulos, S., Triandopoulos, N., Zacharias, T.: Delegatable pseudorandom functions and applications. In: Sadeghi, A.R., Gligor, V.D., Yung, M. (eds.) ACM CCS 2013, pp. 669\u2013684. ACM Press (2013). https:\/\/doi.org\/10.1145\/2508859.2516668","DOI":"10.1145\/2508859.2516668"},{"key":"3_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1007\/978-3-030-17653-2_3","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"M Kloo\u00df","year":"2019","unstructured":"Kloo\u00df, M., Lehmann, A., Rupp, A.: (R)CCA secure updatable encryption with integrity protection. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019, Part I. LNCS, vol. 11476, pp. 68\u201399. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17653-2_3"},{"key":"3_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"685","DOI":"10.1007\/978-3-319-78372-7_22","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"A Lehmann","year":"2018","unstructured":"Lehmann, A., Tackmann, B.: Updatable encryption with\u00a0post-compromise security. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018, Part III. LNCS, vol. 10822, pp. 685\u2013716. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_22"},{"key":"3_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"298","DOI":"10.1007\/978-3-030-57990-6_15","volume-title":"Security and Cryptography for Networks","author":"DE Lucani","year":"2020","unstructured":"Lucani, D.E., Nielsen, L., Orlandi, C., Pagnin, E., Vestergaard, R.: Secure generalized deduplication via multi-key revealing encryption. In: Galdi, C., Kolesnikov, V. (eds.) SCN 2020. LNCS, vol. 12238, pp. 298\u2013318. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-57990-6_15"},{"key":"3_CR27","unstructured":"Marlinspike, M., Perrin, T.: The double ratchet algorithm (2016). https:\/\/whispersystems.org\/docs\/specifications\/doubleratchet\/doubleratchet.pdf"},{"key":"3_CR28","unstructured":"Slamanig, D., Striecks, C.: Revisiting updatable encryption: controlled forward security, constructions and a puncturable perspective. Cryptology ePrint Archive, Paper 2021\/268 (2021). https:\/\/eprint.iacr.org\/2021\/268"},{"key":"3_CR29","unstructured":"WhatsApp: How WhatsApp enables multi-device capability (2021). https:\/\/engineering.fb.com\/2021\/07\/14\/security\/whatsapp-multi-device\/. Retrieved Oct 2022"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-68379-4_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T00:04:36Z","timestamp":1786752276000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-68379-4_3"}},"subtitle":["A Modern Approach to Key Backup and Delegation"],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031683787","9783031683794"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-68379-4_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"16 August 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 August 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 August 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"44","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}