System-wide Auditability Through Cryptographic Techniques

The Hong Kong University of Science and Technology
Department of Computer Science and Engineering


PhD Thesis Defence


Title: "System-wide Auditability Through Cryptographic Techniques"

By

Mr. Vlasios KOUTSOS


Abstract:

Outsourcing data and computation to powerful servers is standard in modern 
computing. On the one hand, services and applications generally require users 
to relinquish control of their data and trust the provider for correctly 
executing the desired functionalities on it. On the other, providers usually 
cannot evaluate the quality of user-provided data. This is especially 
problematic in cases where sensitive data is required and entities with 
competing interests do not trust each other. In fact, to overcome these 
issues, an external verifier often regulates the system's functionality, 
raising the following, fundamental issue: How can trust be alleviated from 
both sides, and how can an external entity verify the system's correctness.

Auditability comes in various shapes and forms, but at its core it is an 
add-on feature mainly serving the following purpose: It enables external 
entities to verify the system's functionality, safeguarding participants from 
malicious behaviours, offering overall a notion of control. Interestingly, 
existing cryptographic techniques can and have been used to realize 
auditability features for various settings, however, introducing complex 
notions of auditability as mentioned above at a wider, system level is not 
trivial. This thesis presents three novel auditability-focused schemes, where 
specialized protocols are designed, supporting different auditing notions, 
tailored for each different target application's intricacies. First, it 
introduces publicly auditable functional encryption, a direct 
function-agnostic extension to a popular cryptographic scheme. Next, it 
presents a cryptographic protocol for financial auditing, where a committee 
can verify the system-level correctness without accessing any underlying data 
in raw, plaintext format. Last, a protocol for crowdsourcing is introduced 
reconciling the properties of anonymity with verifiable task execution and 
payments; properties inherently incompatible with each other.


Date:                   Tuesday, 25 August 2026

Time:                   9:00am - 11:00am

Venue:                  Room 5501
                        Lifts 25-26

Chairman:               Prof. Ilias DIMITRAKOPOULOS (CIVL)

Committee Members:      Dr. Dimitrios PAPADOPOULOS (Supervisor)
                        Prof. Charles ZHANG
                        Dr. Mingxun ZHOU
                        Prof. Allen HUANG (ACCT)
                        Dr. Foteini BALDIMTSI (George Mason University)