Paper 2026/447
Trace: Complete Client-Side Account Access Logging
Abstract
Despite improvements to authentication mechanisms, account compromise remains frequent and users need a trustworthy way to determine what devices have accessed their accounts. Doing so, however, is in tension with privacy goals on the modern web, which mandate that web services not learn static device identifiers. Recent work aims to address this tension via client-side encrypted access logging (CSAL), but their approach does not allow retrieving all log entries and users may miss information about adversarial accesses. We present Trace, a new CSAL system that achieves complete logging while preserving privacy. Trace records verifiable evidence of each authentication in an encrypted log stored by an independent logging service, ensuring that only the user can inspect it. The web service remains unaware of the logging, preserving backward compatibility with existing authentication infrastructures. Unlike prior approaches, Trace simultaneously achieves verifiable device attribution, backward compatibility, and formally-analyzed security against malicious adversaries. Our prototype implementation reaches over 10 K authentications per second on a single core, suggesting it can scale efficiently for large services.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Encrypted Access LoggingAccount Security InterfaceVerifiable Device IdentifiersOPRFAccount Security
- Contact author(s)
-
mail @ paul-gerhart de
co255 @ cornell edu
ristenpart @ cs toronto edu - History
- 2026-03-05: approved
- 2026-03-04: received
- See all versions
- Short URL
- https://ia.cr/2026/447
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/447,
author = {Paul Gerhart and Carolina Ortega Pérez and Thomas Ristenpart},
title = {Trace: Complete Client-Side Account Access Logging},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/447},
year = {2026},
url = {https://eprint.iacr.org/2026/447}
}