Paper 2025/2026

Whom do you trust? PRISM: Lightweight Key Transparency for All

Sebastian Pusch, Philipp University of Marburg
Ryan Quinn Ford, Philipp University of Marburg
Joachim von zur Gathen, University of Bonn
Alexander Markowetz, Philipp University of Marburg
Abstract

End-to-end encrypted (E2EE) messaging platforms serving hundreds of millions of users face a fundamental vulnerability: users must trust service providers to distribute authentic public keys. This problem creates opportunities for sophisticated man-in-the-middle attacks and surveillance. While key transparency systems promise to eliminate this trust requirement, existing solutions have failed to achieve practical deployment due to prohibitive cost in computation and bandwidth, and inadequate infrastructure. Our main innovation is the integration of a zero-knowledge virtual machine to create a “rollup” architecture on a third-party data availability layer via which every user automatically checks the integrity of the whole key directory. Counterintuitively, this approach yields substantial performance improvements over custom-built zk proof circuits and enables verification of targeted policies within the cryptographic proof system. We introduce PRISM, the first practically deployable key transparency protocol that eliminates hidden backdoors in E2EE services through automatic, trust-minimized verification. Our system advances beyond previous approaches by proving not just structural validity of key directory updates, but their semantic correctness as well. Previous solutions require some form of manual interaction by the user. This burden prevented wide spread adoption. Our solution however eliminates user intervention entirely. This paper is intended as an overview rather than an exhaustive specification. Our implemented system already integrates additional components whose full complexity exceeds the scope of this short presentation.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
key transparencydata availabilitySTARKSNARKmessagingE2EE
Contact author(s)
sebastianpusch @ acm org
ryanquinnford @ acm org
gathen @ bit uni-bonn de
markowet @ informatik uni-marburg de
History
2025-11-03: approved
2025-10-31: received
See all versions
Short URL
https://ia.cr/2025/2026
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2026,
      author = {Sebastian Pusch and Ryan Quinn Ford and Joachim von zur Gathen and Alexander Markowetz},
      title = {Whom do you trust? {PRISM}: Lightweight Key Transparency for All},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2026},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2026}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.