Secure Asynchronous Reactive Systems

Secure Asynchronous Reactive Systems
复制标题

安全异步反应系统

DOI:
--
复制
发表时间:
2004
期刊:
影响因子:
--
通讯作者:
M. Waidner
M. Waidner
中科院分区:
--
文献类型:
--
作者:
M. Backes;B. Pfitzmann;M. Waidner

文献摘要

被引文献

相似文献

我们提出了一个严格的模型,在异步网络中的安全反应式系统。它捕获了密码学所需的安全性的计算方面,以及典型定理证明器和模型检查器所需的抽象,在抽象层内部和之间具有清晰的细化关系。术语“反应式”意味着系统与其用户多次交互,例如,在许多并发协议运行中。我们定义了一个分布式调度方案,允许概率执行与现实的对抗调度和本地子机的表示。多项式运行时在反应的情况下被精确地定义,以捕捉多项式有界的用户和对手,以及在更强大的对手的存在下运行时受限的机器的动作。该模型捕获了最强的可能对抗行为,但以模块化的方式定义,以便可以考虑其他信任模型,例如,一些安全的或可信的通道和静态的或适应性的对手。安全保护精化与普通精化不同,因为它包含机密性。我们捕捉它的概念反应模拟性,扩展现有的加密概念,从更简单的情况下,一般反应的情况下。
We present a rigorous model for secure reactive systems in asynchronous networks. It captures both computational aspects of security as needed for cryptography, and abstractions as needed in typical theorem provers and model checkers, with clear refinement relations within and between the layers of abstraction. The term “reactive” means that the system interacts with its users multiple times, e.g., in many concurrent protocol runs. We define a distributed scheduling scheme that allows both probabilistic executions with realistic adversarial scheduling and the representation of local submachines. Polynomial runtime in the reactive case is defined precisely, to capture polynomially bounded users and adversaries, as well as actions of runtime-restricted machines in the presence of more powerful adversaries. The model captures the strongest possible adversarial behaviors, but is defined in a modular way so that other trust models can be considered, e.g., some secure or authentic channels and static or adaptive adversaries. Security-preserving refinement is different from normal refinement because it includes confidentiality. We capture it by the notion of reactive simulatability, extending existing cryptographic notions from much simpler scenarios to the general reactive case.