Collusion-Minimized TLS Attestation Protocol for Decentralized Applications
IEEE Transactions on Dependable and Secure Computing, cilt.23, sa.5, ss.9730-9746, 2026 (SCI-Expanded, Scopus)
- Yayın Türü: Makale / Tam Makale
- Cilt numarası: 23 Sayı: 5
- Basım Tarihi: 2026
- Doi Numarası: 10.1109/tdsc.2026.3716834
- Dergi Adı: IEEE Transactions on Dependable and Secure Computing
- Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus, ABI/INFORM, Aerospace Database, Compendex, INSPEC, Materials Science & Engineering Collection (ProQuest), Technology Collection (ProQuest)
- Sayfa Sayıları: ss.9730-9746
- Anahtar Kelimeler: attestation, Interoperability, oracles, smart contracts, threshold signatures, transport layer security
- Orta Doğu Teknik Üniversitesi Adresli: Evet
Özet
Transport Layer Security (TLS) attestation protocols are a key building block for decentralized applications that require authenticated off-chain data. However, existing Designed Commitment TLS (DCTLS) constructions rely on designated verifiers, which prevents public verifiability and enables prover-verifier collusion in on-chain settings. To address these limitations, we propose a collusion-minimized TLS attestation framework Πcoll-min that extends existing DCTLS protocols to support jointly verifiable attestations with distributed verifiers. The framework combines two complementary components: dx-DCTLS, a generic transformation layer that upgrades existing DCTLS constructions into exportable variants by replacing non-verifiable components with verifiable counterparts, and a decentralized validation layer based on distributed verifiable random functions (DVRFs) and a threshold signature scheme (TSS). Together, these two components allow multiple verifiers to jointly validate TLS attestations while minimizing prover-verifier collusion. In this study, we formalize a threshold attestation unforgeability notion capturing adversarial behaviors in multi-verifier environments and prove security under standard assumptions. Specifically, by transitioning from independent multi-session validations, as commonly employed in decentralized oracle networks (DONs), to a unified and exportable attestation framework, we eliminate the per-verifier repetition on the prover side. Consequently, the prover complexity is reduced from O(n) to O(1). To evaluate practicality, we provide an end-to-end prototype implementation of Πcoll-min and compare it against a DECO-based replication baseline. The results show that the proposed framework remains efficient at high threshold sizes and introduces only modest additional overhead, demonstrating the feasibility of collusion-minimized and jointly verifiable TLS attestations for smart contract environments.