Robust Channels: Handling Unreliable Networks in the Record Layers of QUIC and DTLS 1.3

Robust Channels: Handling Unreliable Networks in the Record Layers of QUIC and DTLS 1.3
复制标题

稳健的通道:处理 QUIC 和 DTLS 1.3 记录层中的不可靠网络

DOI:
--
复制
发表时间:
2024
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Christian Janson
Christian Janson
中科院分区:
--
文献类型:
--
作者:
M. Fischlin;Felix Günther;Christian Janson

文献摘要

参考文献

被引文献

相似文献

安全通信信道协议中的常见方法是依赖于按顺序到达的密文,并在任何恶意密文时关闭连接。通道的密码安全模型通常反映了这种设计。当运行在较低级别的传输协议(如TCP)上时,这是合理的,以确保按顺序传输,例如TLS或SSH。然而,像QUIC或DTLS这样的协议在UDP等不可靠的传输上运行,如果数据包丢失或以不同的顺序到达,它们不会关闭连接,事实上也不能关闭连接。相反,这些协议必须小心地捕捉不可靠网络中自然产生的影响,通常通过使用滑动窗口技术,只要密文没有错位太远,就可以正确解密。为了能够捕获QUIC和最新的DTLS版本1.3,我们引入了加密通道鲁棒性的广义概念。此属性可以捕获不可靠的网络行为,并保证对抗性篡改不会阻碍可以正确解密的密文被接受。我们表明,鲁棒性是正交的通道的完整性的共同概念,但连同完整性和选择明文的安全性,它提供了一个强大的模拟选择密文的安全通道。与以前的工作相比,鲁棒性使我们能够研究数据包加密的记录层协议的QUIC和DTLS 1.3和新的滑动窗口技术,这两个协议采用。我们表明,这两个协议实现强大的选择密文安全的基础上,他们的滑动窗口技术和底层AEAD计划的某些属性。值得注意的是,处理不可靠网络消息所需的鲁棒性要求两个记录层协议都能容忍重复的对抗性伪造尝试。这意味着我们只能建立非严格的安全边界(就AEAD完整性而言),这是早期协议草案中遗漏的安全降级。我们的界限导致负责的IETF工作组为这两个协议引入了具体的伪造限制,IRTF CFRG更广泛地考虑了AEAD的使用限制。
The common approach in secure communication channel protocols is to rely on ciphertexts arriving in-order and to close the connection upon any rogue ciphertext. Cryptographic security models for channels generally reflect such design. This is reasonable when running atop lower-level transport protocols like TCP ensuring in-order delivery, as for example, is the case with TLS or SSH. However, protocols like QUIC or DTLS which run over a non-reliable transport such as UDP, do not—and in fact cannot—close the connection if packets are lost or arrive in a different order. Those protocols instead have to carefully catch effects arising naturally in unreliable networks, usually by using a sliding-window technique where ciphertexts can be decrypted correctly as long as they are not misplaced too far. In order to be able to capture QUIC and the newest DTLS version 1.3, we introduce a generalized notion of robustness of cryptographic channels. This property can capture unreliable network behavior and guarantees that adversarial tampering cannot hinder ciphertexts that can be decrypted correctly from being accepted. We show that robustness is orthogonal to the common notion of integrity for channels, but together with integrity and chosen-plaintext security it provides a robust analog of chosen-ciphertext security of channels. In contrast to prior work, robustness allows us to study packet encryption in the record layer protocols of QUIC and of DTLS 1.3 and the novel sliding-window techniques both protocols employ. We show that both protocols achieve robust chosen-ciphertext security based on certain properties of their sliding-window techniques and the underlying AEAD schemes. Notably, the robustness needed in handling unreliable network messages requires both record layer protocols to tolerate repeated adversarial forgery attempts. This means we can only establish non-tight security bounds (in terms of AEAD integrity), a security degradation that was missed in earlier protocol drafts. Our bounds led the responsible IETF working groups to introduce concrete forgery limits for both protocols and the IRTF CFRG to consider AEAD usage limits more broadly.
简化基于游戏的定义:从不可区分性到正确性及其在状态 AE 中的应用
DOI: 10.1007/2f978-3-319-96881-0_1
发表时间: 2019
期刊: Advances in Crytology -- CRYPTO 2018
影响因子: --
作者:
Rogaway, Phillip;Zhang, Yusi
通讯作者: Zhang, Yusi
DOI: 10.1145/3243734.3243816
发表时间: 2018-10
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
V. Hoang;Stefano Tessaro;Aishwarya Thiruvengadam
通讯作者: V. Hoang;Stefano Tessaro;Aishwarya Thiruvengadam
部分指定通道:没有省略的 TLS 1.3 记录层
DOI: 10.1145/3243734.3243789
发表时间: 2018
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Patton, Christopher;Shrimpton, Thomas
通讯作者: Shrimpton, Thomas
IETF QUIC 记录层的安全模型和经过充分验证的实现
DOI: --
发表时间: 2021
期刊: Proceedings of the IEEE Symposium on Security and Privacy
影响因子: --
作者:
Delignat-Lavaud, Antoine;Fournet, Cédric;Parno, Bryan;Protzenko, Jonathan;Ramananandro, Tahina;Bosamiya, Jay;Lallemand, Joseph;Rakotonirina, Itsaka;Zhou, Yi
通讯作者: Zhou, Yi