Delayed Authentication: Preventing Replay and Relay Attacks in Private Contact Tracing

Delayed Authentication: Preventing Replay and Relay Attacks in Private Contact Tracing
复制标题

延迟身份验证:防止私人联系人追踪中的重放和中继攻击

DOI:
10.1007/978-3-030-65277-7_1
复制
发表时间:
2020
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Krzysztof Pietrzak
Krzysztof Pietrzak
中科院分区:
--
文献类型:
--
作者:
Krzysztof Pietrzak

文献摘要

被引文献

相似文献

目前,有几个项目旨在设计和实施保护隐私的自动接触者追踪协议,以帮助抗击当前的大流行。这些建议非常相似,其最基本的形式基本上是提出一款手机应用程序,该应用程序通过(低功耗)蓝牙广播频繁变化的伪随机标识符,同时,应用程序商店id广播在其附近的手机只有当用户检测呈阳性时,在过去两周左右的时间里,他们上传了他们广播的信标(就像DP-3T、东海岸和西海岸PACT或Covid watch这样的去中心化提案)或收到的信标(就像Popp-PT或ROBERT那样)。Vaudenay [eprint 2020/399]观察到,这个基本方案(他认为DP-3T提案)屈服于中继甚至重放攻击。并提出了更复杂的交互方案,在不放弃太多隐私方面的情况下防止这些攻击不幸的是,出于效率和安全原因,交互对于这个应用程序来说是有问题的。到目前为止,已经提出的对策要么不实用,要么放弃了关键的隐私方面。我们提出了一个简单的非交互的基本协议变体,(安全)可以证明防止重播和(如果位置数据可用)中继攻击(隐私)数据广播的消息可以容纳128位,只使用基本的加密(承诺和密钥认证)为此,我们引入了“延迟认证”的概念,它基本上是一个消息认证码,验证可以分两步完成,第一步不需要密钥;第二种不需要信息©施普林格Nature Switzerland AG 2020
Currently several projects aim at designing and implementing protocols for privacy preserving automated contact tracing to help fight the current pandemic Those proposal are quite similar, and in their most basic form basically propose an app for mobile phones which broadcasts frequently changing pseudorandom identifiers via (low energy) Bluetooth, and at the same time, the app stores IDs broadcast by phones in its proximity Only if a user is tested positive, they upload either the beacons they did broadcast (which is the case in decentralized proposals as DP-3T, east and west coast PACT or Covid watch) or received (as in Popp-PT or ROBERT) during the last two weeks or so Vaudenay [eprint 2020/399] observes that this basic scheme (he considers the DP-3T proposal) succumbs to relay and even replay attacks, and proposes more complex interactive schemes which prevent those attacks without giving up too many privacy aspects Unfortunately interaction is problematic for this application for efficiency and security reasons The countermeasures that have been suggested so far are either not practical or give up on key privacy aspects We propose a simple non-interactive variant of the basic protocol that(security) Provably prevents replay and (if location data is available) relay attacks (privacy) The data of all parties (even jointly) reveals no information on the location or time where encounters happened (efficiency) The broadcasted message can fit into 128 bits and uses only basic crypto (commitments and secret key authentication) Towards this end we introduce the concept of “delayed authentication”, which basically is a message authentication code where verification can be done in two steps, where the first doesn’t require the key, and the second doesn’t require the message © Springer Nature Switzerland AG 2020