Paper 2022/1209

Puncturable Key Wrapping and Its Applications

Matilda Backendal, ETH Zurich
Felix Günther, ETH Zurich
Kenneth G. Paterson, ETH Zurich

We introduce puncturable key wrapping (PKW), a new cryptographic primitive that supports fine-grained forward security properties in symmetric key hierarchies. We develop syntax and security definitions, along with provably secure constructions for PKW from simpler components (AEAD schemes and puncturable PRFs). We show how PKW can be applied in two distinct scenarios. First, we show how to use PKW to achieve forward security for TLS 1.3 0-RTT session resumption, even when the server's long-term key for generating session tickets gets compromised. This extends and corrects a recent work of Aviram, Gellert, and Jager (Journal of Cryptology, 2021). Second, we show how to use PKW to build a protected file storage system with file shredding, wherein a client can outsource encrypted files to a potentially malicious or corrupted cloud server whilst achieving strong forward-security guarantees, relying only on local key updates.

Note: Add key rap.

Available format(s)
Secret-key cryptography
Publication info
A major revision of an IACR publication in ASIACRYPT 2022
Puncturing Forward security Key wrapping PPRF TLS Protected file storage
Contact author(s)
mbackendal @ inf ethz ch
mail @ felixguenther info
kenny paterson @ inf ethz ch
2022-12-04: revised
2022-09-13: received
See all versions
Short URL
Creative Commons Attribution


      author = {Matilda Backendal and Felix Günther and Kenneth G. Paterson},
      title = {Puncturable Key Wrapping and Its Applications},
      howpublished = {Cryptology ePrint Archive, Paper 2022/1209},
      year = {2022},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.