Paper 2026/2187

Rethinking Zero-Knowledge TLS: Proof of Protocol Execution and the Reclaim Protocol

Andrey Bozhko, University of Luxembourg
Kirill Kutsenok, Reclaim Protocol, King's College London
Abstract

In a zkTLS protocol, a user proves to a third party a property of data obtained from an online service over TLS, revealing nothing beyond the statement proven. Each existing scheme, however, comes with its own security model, written for that scheme alone, so the schemes are not proven secure against a common definition. The root cause is a mismatch of levels: existing models are stated at the level of TLS and therefore reflect how each construction handles it. Yet TLS is only the transport, and a zkTLS proof is about the application-layer protocol executed over it. We therefore introduce the first transport-agnostic security model for zkTLS, stated at the application layer and mentioning neither TLS nor any particular construction. The resulting notion, Zero-Knowledge Proof of Protocol Execution (zkPoPE), defines what it means for a party that has executed an arbitrary two-party protocol with a counterparty to prove, in zero knowledge, that its private input and the reply it received satisfy a chosen property, and, crucially, that the reply comes from a real execution with that counterparty rather than being fabricated. This proof-of-execution requirement separates zkPoPE from a NIZK over the input--reply pair: knowing a satisfying pair does not by itself show that an execution occurred. We formalize zkPoPE as a UC ideal functionality F_{zkpope}. We then introduce the Reclaim Protocol, a zkTLS scheme that UC-realizes F_{zkpope} under a deployment-aligned trust model and underlies a production system. Reclaim builds on Distributed-AEAD, a new three-party authenticated-encryption primitive of independent interest. On a lower-mid-range phone, Reclaim attests to a 1200kB response in 7.28s, two orders of magnitude beyond any size previously benchmarked for zkTLS.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Contact author(s)
andrey bozhko @ uni lu
kirill @ reclaimprotocol org
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2187
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2187,
      author = {Andrey Bozhko and Kirill Kutsenok},
      title = {Rethinking Zero-Knowledge {TLS}: Proof of Protocol Execution and the Reclaim Protocol},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2187},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2187}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.