Paper 2026/2187
Rethinking Zero-Knowledge TLS: Proof of Protocol Execution and the Reclaim Protocol
Abstract
In a zkTLS protocol, a user proves to a third party a property of data obtained from an online service over TLS, revealing nothing beyond the statement proven. Each existing scheme, however, comes with its own security model, written for that scheme alone, so the schemes are not proven secure against a common definition. The root cause is a mismatch of levels: existing models are stated at the level of TLS and therefore reflect how each construction handles it. Yet TLS is only the transport, and a zkTLS proof is about the application-layer protocol executed over it. We therefore introduce the first transport-agnostic security model for zkTLS, stated at the application layer and mentioning neither TLS nor any particular construction. The resulting notion, Zero-Knowledge Proof of Protocol Execution (zkPoPE), defines what it means for a party that has executed an arbitrary two-party protocol with a counterparty to prove, in zero knowledge, that its private input and the reply it received satisfy a chosen property, and, crucially, that the reply comes from a real execution with that counterparty rather than being fabricated. This proof-of-execution requirement separates zkPoPE from a NIZK over the input--reply pair: knowing a satisfying pair does not by itself show that an execution occurred. We formalize zkPoPE as a UC ideal functionality F_{zkpope}. We then introduce the Reclaim Protocol, a zkTLS scheme that UC-realizes F_{zkpope} under a deployment-aligned trust model and underlies a production system. Reclaim builds on Distributed-AEAD, a new three-party authenticated-encryption primitive of independent interest. On a lower-mid-range phone, Reclaim attests to a 1200kB response in 7.28s, two orders of magnitude beyond any size previously benchmarked for zkTLS.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Contact author(s)
-
andrey bozhko @ uni lu
kirill @ reclaimprotocol org - History
- 2026-09-26: approved
- 2026-09-23: received
- See all versions
- Short URL
- https://ia.cr/2026/2187
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2187,
author = {Andrey Bozhko and Kirill Kutsenok},
title = {Rethinking Zero-Knowledge {TLS}: Proof of Protocol Execution and the Reclaim Protocol},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2187},
year = {2026},
url = {https://eprint.iacr.org/2026/2187}
}