Pub/sub messaging is one of the most widely used communication mechanisms in modern distributed systems. It relies on a centralized broker that routes messages among clients and also acts as a policy enforcement point, storing the access-control policy and enforcing it by deciding who may publish to a topic and who may subscribe. An untrusted broker completely subverts the security of such systems, compromising both the confidentiality and authenticity of the data and the correctness of authorization. To address this, we introduce PCP (Proof-Carrying Payloads), an end-to-end authorization overlay that moves both data protection and authorization from the broker to the clients. PCP is broker-agnostic and deploys as a wrapper around an existing pub/sub system, without modifying the broker. In PCP, each message is a cryptographic envelope that carries a succinct zero-knowledge proof establishing that its publisher holds a valid write credential; a subscriber verifies this proof before attempting to decrypt the envelope, while the encryption itself enforces read authorization. PCP further introduces a two-tier authorization revocation mechanism: one tier revokes publishers, and the other revokes subscribers. We present the design of PCP together with a formal analysis of its security. On the design side, we define the system entities and their trust relationships, the enrollment protocols through which publishers and subscribers obtain their credentials, the wrapping procedures that turn an ordinary publish or receive operation into a proof-carrying, encrypted exchange, and the protocols that implement two-tier revocation. On the analysis side, we first state the threat model and the security goals, and then prove that PCP meets them. Goals expressible at the protocol level are verified symbolically in the Tamarin prover, while those that rely on the computational hardness of the underlying cryptographic primitives are established by hand, through standard game-based reductions.

Proof-carrying payloads: end-to-end authorization for Pub/Sub messaging / Galletta, L.. - In: THE JOURNAL OF LOGICAL AND ALGEBRAIC METHODS IN PROGRAMMING. - ISSN 2352-2208. - 152:(2027). [10.1016/j.jlamp.2026.101173]

Proof-carrying payloads: end-to-end authorization for Pub/Sub messaging

Galletta Letterio
2027

Abstract

Pub/sub messaging is one of the most widely used communication mechanisms in modern distributed systems. It relies on a centralized broker that routes messages among clients and also acts as a policy enforcement point, storing the access-control policy and enforcing it by deciding who may publish to a topic and who may subscribe. An untrusted broker completely subverts the security of such systems, compromising both the confidentiality and authenticity of the data and the correctness of authorization. To address this, we introduce PCP (Proof-Carrying Payloads), an end-to-end authorization overlay that moves both data protection and authorization from the broker to the clients. PCP is broker-agnostic and deploys as a wrapper around an existing pub/sub system, without modifying the broker. In PCP, each message is a cryptographic envelope that carries a succinct zero-knowledge proof establishing that its publisher holds a valid write credential; a subscriber verifies this proof before attempting to decrypt the envelope, while the encryption itself enforces read authorization. PCP further introduces a two-tier authorization revocation mechanism: one tier revokes publishers, and the other revokes subscribers. We present the design of PCP together with a formal analysis of its security. On the design side, we define the system entities and their trust relationships, the enrollment protocols through which publishers and subscribers obtain their credentials, the wrapping procedures that turn an ordinary publish or receive operation into a proof-carrying, encrypted exchange, and the protocols that implement two-tier revocation. On the analysis side, we first state the threat model and the security goals, and then prove that PCP meets them. Goals expressible at the protocol level are verified symbolically in the Tamarin prover, while those that rely on the computational hardness of the underlying cryptographic primitives are established by hand, through standard game-based reductions.
2027
Attribute-based encryption
Protocol verification
Zero-knowledge proofs
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S2352220826000659-main.pdf

Accesso aperto

Descrizione: Proof-carrying payloads: End-to-end authorization for Pub/Sub messaging
Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 7.62 MB
Formato Adobe PDF
7.62 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.11771/44418
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • OpenAlex ND
social impact