{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T17:51:39Z","timestamp":1785433899628,"version":"3.56.0"},"reference-count":51,"publisher":"International Association for Cryptologic Research","issue":"2","license":[{"start":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T00:00:00Z","timestamp":1736812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001656","name":"Helmholtz-Gemeinschaft","doi-asserted-by":"publisher","award":["46.23.01"],"award-info":[{"award-number":["46.23.01"]}],"id":[{"id":"10.13039\/501100001656","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,6,2]]},"abstract":"<jats:p>Many user-centric applications face a common privacy problem: the need to collect, store, and analyze sensitive user data. Examples include check-in\/check-out based payment systems for public transportation, charging\/discharging electric vehicle batteries in smart grids, coalition loyalty programs, behavior-based car insurance, and more. We propose and evaluate a generic solution to this problem. More specifically, we provide a formal framework integrating privacy-preserving data collection, storage, and analysis, which can be used for many different application scenarios, present an instantiation, and perform an experimental evaluation of its practicality.<\/jats:p>\n                  <jats:p>We consider a setting where multiple operators (e.g., different mobility providers, different car manufacturers and insurance companies), who do not fully trust each other, intend to maintain and analyze data produced by the union of their user sets. The data is collected in an anonymous (wrt. all operators) but authenticated way and stored in so-called user logbooks. In order for the operators to be able to perform analyses at any time without requiring user interaction, the logbooks are kept on the operator's side. Consequently, this potentially sensitive data must be protected from unauthorized access. To achieve this, we combine several selected cryptographic techniques, such as threshold signatures and oblivious RAM. The latter ensures that user anonymity is protected even against memory access pattern attacks.<\/jats:p>\n                  <jats:p>To the best of our knowledge, we provide and evaluate the first generic framework that combines data collection, operator-side data storage, and data analysis in a privacy-preserving manner, while providing a formal security model, a UC-secure protocol, and a full implementation. With three operators, our implementation can handle over two million new logbook entries per day.<\/jats:p>","DOI":"10.62056\/av11zo-3y","type":"journal-article","created":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T17:09:09Z","timestamp":1751908149000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["POBA: Privacy-Preserving Operator-Side Bookkeeping and Analytics"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-4682-7008","authenticated-orcid":false,"given":"Dennis","family":"Faut","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04t3en479","id-type":"ROR","asserted-by":"publisher"}],"name":"Karlsruhe Institute of Technology","place":["Am Fasanengarten 5, Karlsruhe, Germany, 76137, Germany"],"department":["KASTEL"]},{"id":[{"id":"https:\/\/ror.org\/036x5ad56","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Luxembourg","place":["Esch-sur-Alzette, Luxembourg"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-8157-9768","authenticated-orcid":false,"given":"Valerie","family":"Fetzer","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04t3en479","id-type":"ROR","asserted-by":"publisher"}],"name":"Karlsruhe Institute of Technology","place":["Am Fasanengarten 5, Karlsruhe, Germany, 76137, Germany"],"department":["KASTEL"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0362-0519","authenticated-orcid":false,"given":"J\u00f6rn","family":"M\u00fcller-Quade","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04t3en479","id-type":"ROR","asserted-by":"publisher"}],"name":"Karlsruhe Institute of Technology","place":["Am Fasanengarten 5, Karlsruhe, Germany, 76137, Germany"],"department":["KASTEL"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6449-9494","authenticated-orcid":false,"given":"Markus","family":"Raiber","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/04t3en479","id-type":"ROR","asserted-by":"publisher"}],"name":"Karlsruhe Institute of Technology","place":["Am Fasanengarten 5, Karlsruhe, Germany, 76137, Germany"],"department":["KASTEL"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0439-3633","authenticated-orcid":false,"given":"Andy","family":"Rupp","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/036x5ad56","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Luxembourg","place":["Esch-sur-Alzette, Luxembourg"]},{"name":"KASTEL Security Research Labs","place":["Karlsruhe, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,7,7]]},"reference":[{"key":"ref1:AC:KelSch14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"506","DOI":"10.1007\/978-3-662-45608-8_27","article-title":"Efficient, Oblivious Data Structures for MPC","volume":"8874","author":"Marcel Keller","year":"2014"},{"key":"ref2:EC:GroSah08","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1007\/978-3-540-78967-3_24","article-title":"Efficient Non-interactive Proof Systems for Bilinear\n  Groups","volume":"4965","author":"Jens Groth","year":"2008"},{"key":"ref3:au2013new","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1109\/TVT.2013.2274288","article-title":"A New Payment System for Enhancing Location Privacy of\n  Electric Vehicles","volume":"63","author":"Man Ho Au","year":"2014","journal-title":"IEEE Transactions on Vehicular Technology"},{"key":"ref4:C:HofJag12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"590","DOI":"10.1007\/978-3-642-32009-5_35","article-title":"Tightly Secure Signatures and Public-Key Encryption","volume":"7417","author":"Dennis Hofheinz","year":"2012"},{"key":"ref5:CCS:ErlPihKor14","doi-asserted-by":"publisher","first-page":"1054","DOI":"10.1145\/2660267.2660348","article-title":"RAPPOR: Randomized Aggregatable Privacy-Preserving Ordinal\n  Response","author":"\u00dalfar Erlingsson","year":"2014"},{"key":"ref6:DBLP:conf\/nsdi\/Corrigan-GibbsB17","first-page":"259","article-title":"Prio: Private, Robust, and Scalable Computation of Aggregate\n  Statistics","author":"Henry Corrigan-Gibbs","year":"2017"},{"key":"ref7:kerschbaumPrivacypreservingBillingEticketing2013","series-title":"WPES '13","isbn-type":"print","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1145\/2517840.2517848","article-title":"Privacy-Preserving Billing for e-Ticketing Systems in Public\n  Transportation","author":"Florian Kerschbaum","year":"2013","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450324854"},{"key":"ref8:AC:BonDriNev18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1007\/978-3-030-03329-3_15","article-title":"Compact Multi-signatures for Smaller Blockchains","volume":"11273","author":"Dan Boneh","year":"2018"},{"key":"ref9:yue2024pap","doi-asserted-by":"publisher","first-page":"6092","DOI":"10.1109\/TSG.2024.3435028","article-title":"PAP: A Privacy-Preserving Authentication Scheme With\n  Anonymous Payment for V2G Networks","volume":"15","author":"Xiaohan Yue","year":"2024","journal-title":"IEEE Transactions on Smart Grid"},{"key":"ref10:PKC:EscGro14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"630","DOI":"10.1007\/978-3-642-54631-0_36","article-title":"Fine-Tuning Groth-Sahai Proofs","volume":"8383","author":"Alex Escala","year":"2014"},{"key":"ref11:jorns2007privacy","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1109\/ARES.2007.16","article-title":"A Privacy Enhancing Service Architecture for Ticket-based\n  Mobile Applications","author":"Oliver Jorns","year":"2007"},{"key":"ref12:CCS:BPRS23","doi-asserted-by":"publisher","first-page":"3284","DOI":"10.1145\/3576915.3623115","article-title":"Ramen: Souper Fast Three-Party Computation for RAM\n  Programs","author":"Lennart Braun","year":"2023"},{"key":"ref13:PoPETS:FKMRRS22","doi-asserted-by":"publisher","first-page":"447","DOI":"10.2478\/popets-2022-0054","article-title":"PUBA: Privacy-Preserving User-Data Bookkeeping and\n  Analytics","volume":"2022","author":"Valerie Fetzer","year":"2022","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"ref14:chen2024post","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TIV.2024.3374724","article-title":"A Post-Quantum Privacy-Preserving Payment Protocol in\n  Vehicle to Grid Networks","author":"Ying Chen","year":"2024","journal-title":"IEEE Transactions on Intelligent Vehicles"},{"key":"ref15:SP:BBCGI21","doi-asserted-by":"publisher","first-page":"762","DOI":"10.1109\/SP40001.2021.00048","article-title":"Lightweight Techniques for Private Heavy Hitters","author":"Dan Boneh","year":"2021"},{"key":"ref16:CCS:SDSFRY13","doi-asserted-by":"publisher","first-page":"299","DOI":"10.1145\/2508859.2516660","article-title":"Path ORAM: an extremely simple oblivious RAM protocol","author":"Emil Stefanov","year":"2013"},{"key":"ref17:PoPETS:MouSarTso24","doi-asserted-by":"publisher","first-page":"4","DOI":"10.56553\/popets-2024-0064","article-title":"PLASMA: Private, Lightweight Aggregated Statistics against\n  Malicious Adversaries","volume":"2024","author":"Dimitris Mouris","year":"2024","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"ref18:wan2021decentralized","doi-asserted-by":"publisher","first-page":"2442","DOI":"10.1109\/TDSC.2021.3059345","article-title":"Decentralized Privacy-Preserving Fair Exchange Scheme for\n  V2G Based on Blockchain","volume":"19","author":"Zhiguo Wan","year":"2022","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"ref19:DBLP:journals\/eninf\/SchwerdtNFGR19","doi-asserted-by":"publisher","DOI":"10.1186\/S42162-019-0075-1","article-title":"P6V2G: a privacy-preserving V2G scheme for two-way\n  payments and reputation","volume":"2","author":"Rebecca Schwerdt","year":"2019","journal-title":"Energy Inform."},{"key":"ref20:PETS:HCDF06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11957454_1","article-title":"Privacy for Public Transportation","volume":"4258","author":"Thomas S. Heydt-Benjamin","year":"2006"},{"key":"ref21:han2019privacy","doi-asserted-by":"publisher","first-page":"1836","DOI":"10.1109\/TDSC.2019.2940946","article-title":"Privacy-Preserving Electronic Ticket Scheme with\n  Attribute-Based Credentials","volume":"18","author":"Jinguang Han","year":"2021","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"ref22:emp-toolkit","volume-title":"EMP-toolkit: Efficient MultiParty computation toolkit","author":"Xiao Wang","year":"2016"},{"key":"ref23:LC:AraPagRod21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"320","DOI":"10.1007\/978-3-030-88238-9_16","article-title":"LOVE a Pairing","volume":"12912","author":"Diego F. Aranha","year":"2021"},{"key":"ref24:DBLP:journals\/ijisec\/RialDK18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/S10207-016-0355-8","article-title":"Privacy-preserving smart metering revisited","volume":"17","author":"Alfredo Rial","year":"2018","journal-title":"Int. J. Inf. Sec."},{"key":"ref25:PoPETS:ALTDBG15","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1515\/popets-2015-0019","article-title":"A Practical Set-Membership Proof for Privacy-Preserving\n  NFC Mobile Ticketing","volume":"2015","author":"Ghada Arfaoui","year":"2015","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"ref26:AC:Groth06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"444","DOI":"10.1007\/11935230_29","article-title":"Simulation-Sound NIZK Proofs for a Practical Language and\n  Constant Size Group Signatures","volume":"4284","author":"Jens Groth","year":"2006"},{"key":"ref27:USENIX:BGLLMR23","first-page":"4805","article-title":"ACORN: Input Validation for Secure Aggregation","author":"James Bell","year":"2023"},{"key":"ref28:Lindell_Pinkas_2009","doi-asserted-by":"publisher","first-page":"59","DOI":"10.29012\/jpc.v1i1.566","article-title":"Secure Multiparty Computation for Privacy-Preserving Data\n  Mining","volume":"1","author":"Yehuda Lindell","year":"2009","journal-title":"Journal of Privacy and Confidentiality"},{"key":"ref29:EPRINT:Canetti00","volume-title":"Universally Composable Security: A New Paradigm for\n  Cryptographic Protocols","author":"Ran Canetti","year":"2000"},{"key":"ref30:koblitz1987elliptic","doi-asserted-by":"publisher","first-page":"203","DOI":"10.2307\/2007884","article-title":"Elliptic Curve Cryptosystems","volume":"48","author":"Neal Koblitz","year":"1987","journal-title":"Mathematics of Computation","ISSN":"https:\/\/id.crossref.org\/issn\/0025-5718","issn-type":"electronic"},{"key":"ref31:zhaoAnonymousPaymentSystem2014","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/WCSP.2014.6992208","article-title":"An Anonymous Payment System to Protect the Privacy of\n  Electric Vehicles","author":"Tianyu Zhao","year":"2014"},{"key":"ref32:EPRINT:DamTho08","volume-title":"Efficient Conversion of Secret-shared Values Between\n  Different Fields","author":"Ivan Damgard","year":"2008"},{"key":"ref33:CanettiUCjournal","doi-asserted-by":"publisher","DOI":"10.1145\/3402457","article-title":"Universally Composable Security","volume":"67","author":"Ran Canetti","year":"2020","journal-title":"J. ACM","ISSN":"https:\/\/id.crossref.org\/issn\/0004-5411","issn-type":"electronic"},{"key":"ref34:USENIX:FOSZ23","first-page":"3871","article-title":"GigaDORAM: Breaking the Billion Address Barrier","author":"Brett Hemenway Falk","year":"2023"},{"key":"ref35:AC:BonLynSha01","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"514","DOI":"10.1007\/3-540-45682-1_30","article-title":"Short Signatures from the Weil Pairing","volume":"2248","author":"Dan Boneh","year":"2001"},{"key":"ref36:NDSS:MelDanDeC16","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23175","article-title":"Efficient Private Statistics with Succinct Sketches","author":"Luca Melis","year":"2016"},{"key":"ref37:PKC:MMSST24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/978-3-031-57718-5_6","article-title":"Threshold Structure-Preserving Signatures: Strong and\n  Adaptive Security Under Standard Assumptions","volume":"14601","author":"Aikaterini Mitrokotsa","year":"2024"},{"key":"ref38:milutinovic2015privacy","isbn-type":"print","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1007\/978-3-319-20810-7_9","article-title":"Privacy-Preserving Public Transport Ticketing System","author":"Milica Milutinovic","year":"2015","ISBN":"https:\/\/id.crossref.org\/isbn\/9783319208107"},{"key":"ref39:gudymenko2014privacy","series-title":"SIN '14","isbn-type":"print","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1145\/2659651.2659706","article-title":"A Privacy-Preserving E-Ticketing System for Public\n  Transportation Supporting Fine-Granular Billing and Local Validation","author":"Ivan Gudymenko","year":"2014","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450330336"},{"key":"ref40:FC:RHBP13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1007\/978-3-642-39884-1_17","article-title":"P4R: Privacy-Preserving Pre-Payments with Refunds for\n  Transportation Systems","volume":"7859","author":"Andy Rupp","year":"2013"},{"key":"ref41:SAC:BarNae05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/11693383_22","article-title":"Pairing-Friendly Elliptic Curves of Prime Order","volume":"3897","author":"Paulo S. L. M. Barreto","year":"2006"},{"key":"ref42:DBLP:books\/cu\/Goldreich2004","isbn-type":"print","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511721656","volume-title":"The Foundations of Cryptography - Volume 2: Basic\n  Applications","author":"Oded Goldreich","year":"2004","ISBN":"https:\/\/id.crossref.org\/isbn\/0521830842"},{"key":"ref43:relic-toolkit","volume-title":"RELIC is an Efficient LIbrary for Cryptography","author":"D. F. Aranha","year":"2020"},{"key":"ref44:PoPETS:DPRS23","doi-asserted-by":"publisher","first-page":"578","DOI":"10.56553\/popets-2023-0126","article-title":"Verifiable Distributed Aggregation Functions","volume":"2023","author":"Hannah Davis","year":"2023","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"ref45:vives2010electronic","series-title":"MoMM '10","isbn-type":"print","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1145\/1971519.1971585","article-title":"An electronic and secure automatic fare collection system\n  with revocable anonymity for users","author":"Arnau Vives-Guasch","year":"2010","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450304405"},{"key":"ref46:CCS:Keller20","doi-asserted-by":"publisher","first-page":"1575","DOI":"10.1145\/3372297.3417872","article-title":"MP-SPDZ: A Versatile Framework for Multi-Party\n  Computation","author":"Marcel Keller","year":"2020"},{"key":"ref47:SCN:AGJOP22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"516","DOI":"10.1007\/978-3-031-14791-3_23","article-title":"Prio+: Privacy Preserving Aggregate Statistics via Boolean\n  Shares","volume":"13409","author":"Surya Addanki","year":"2022"},{"key":"ref48:STOC:Goldreich87","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1145\/28395.28416","article-title":"Towards a Theory of Software Protection and Simulation by\n  Oblivious RAMs","author":"Oded Goldreich","year":"1987"},{"key":"ref49:JC:ShoGen02","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/s00145-001-0020-9","article-title":"Securing Threshold Cryptosystems against Chosen Ciphertext\n  Attack","volume":"15","author":"Victor Shoup","year":"2002","journal-title":"Journal of Cryptology"},{"key":"ref50:PoPETS:FanPihErl16","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1515\/popets-2016-0015","article-title":"Building a RAPPOR with the Unknown: Privacy-Preserving\n  Learning of Associations and Data Dictionaries","volume":"2016","author":"Giulia C. Fanti","year":"2016","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"ref51:DBLP:conf\/wpes\/RialD11","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1145\/2046556.2046564","article-title":"Privacy-preserving smart metering","author":"Alfredo Rial","year":"2011"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T17:09:24Z","timestamp":1751908164000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/2\/7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,7]]},"references-count":51,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,7,7]]}},"URL":"https:\/\/doi.org\/10.62056\/av11zo-3y","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,7]]},"assertion":[{"value":"2025-01-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-06-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-1-68"}}