Skip to content

LibraryData and agents2019Design paperCorpus record

DECO: proving statements about TLS data without a trusted hardware box

DECO. Fan Zhang, Deepak Maram, Harjasleen Malvai, Steven Goldfeder and Ari Juels.

DECO proposes that a user prove a fact about a TLS session with a website, to a verifier, without putting the session inside trusted hardware.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

DECO proposes that a user prove a fact about a TLS session with a website, to a verifier, without putting the session inside trusted hardware.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
2

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    A proof about a TLS transcript proves what the server sent in that session. It does not prove the server told the truth, and it does not by itself hide the query from the server.

  2. Claim 02 · Paper model

    The proposal

    DECO proposes that a user prove a fact about a TLS session with a website, to a verifier, without putting the session inside trusted hardware.

  3. Claim 03 · Paper model

    The mechanism

    The prover and the verifier jointly participate so the prover cannot splice a fake response, under the paper's construction.

  4. Claim 04 · Paper model

    The bound

    This is a paper. It is not a claim that Chainlink or any product has deployed it unchanged.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    A proof about a TLS transcript proves what the server sent in that session. It does not prove the server told the truth, and it does not by itself hide the query from the server.

    Model

    What has to hold

    You are reading the DECO paper. A product integration is a later document.

    Falsifier

    What would retire it

    What does the origin server learn from the session?

  2. 02 The proposal

    Observation

    What the study says

    DECO proposes that a user prove a fact about a TLS session with a website, to a verifier, without putting the session inside trusted hardware.

    Model

    What has to hold

    The document is the one at the source URL. A marketing page with the same brand is not this text.

    Falsifier

    What would retire it

    What statement about the TLS data is proved?

  3. 03 The mechanism

    Observation

    What the study says

    The prover and the verifier jointly participate so the prover cannot splice a fake response, under the paper's construction.

    Model

    What has to hold

    You are reading the DECO paper. A product integration is a later document.

    Falsifier

    What would retire it

    Who plays the verifier?

  4. 04 The bound

    Observation

    What the study says

    This is a paper. It is not a claim that Chainlink or any product has deployed it unchanged.

    Model

    What has to hold

    You are reading the DECO paper. A product integration is a later document.

    Falsifier

    What would retire it

    What statement about the TLS data is proved?

03 Sequence

One action, as an operating tape

  1. 01The prover and the verifier jointly participate so the prover cannot splice a fake response, under the paper's construction.
  2. 02The statement proved can be a slice of the response, not the whole page. The slice is the application.
  3. 03The TLS endpoint still sees a connection. Privacy against the server is a different goal from authenticity to the verifier.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    DECO proposes that a user prove a fact about a TLS session with a website, to a verifier, without putting the session inside trusted hardware.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    Town Crier's hardware assumption is what this paper is trying to avoid. Do not describe them as the same design.

  2. What actually moves

    The cut

    The statement proved can be a slice of the response, not the whole page. The slice is the application.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

  3. What a later deployment may change

    The cut

    The TLS endpoint still sees a connection. Privacy against the server is a different goal from authenticity to the verifier.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading the DECO paper. A product integration is a later document.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

Town Crier's hardware assumption is what this paper is trying to avoid. Do not describe them as the same design.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

A proof about a TLS transcript proves what the server sent in that session. It does not prove the server told the truth, and it does not by itself hide the query from the server.

What the design proposes

  • The prover and the verifier jointly participate so the prover cannot splice a fake response, under the paper's construction.
  • The statement proved can be a slice of the response, not the whole page. The slice is the application.
  • The TLS endpoint still sees a connection. Privacy against the server is a different goal from authenticity to the verifier.

How the mechanism is specified

  • The prover and the verifier jointly participate so the prover cannot splice a fake response, under the paper's construction.
  • The statement proved can be a slice of the response, not the whole page. The slice is the application.
  • The TLS endpoint still sees a connection. Privacy against the server is a different goal from authenticity to the verifier.

What this page does not treat as proven

  • This is a paper. It is not a claim that Chainlink or any product has deployed it unchanged.
  • It does not state a performance number.
  • Town Crier's hardware assumption is what this paper is trying to avoid. Do not describe them as the same design.

Why the desk still reads it

DECO proposes that a user prove a fact about a TLS session with a website, to a verifier, without putting the session inside trusted hardware.

09 Lexicon

Terms, opened into the record

TLS proof
A proof about bytes from a TLS session. It is not a proof the bytes are true.
Verifier
The party who checks the proof. In a contract setting this has to be named.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.