Authenticated Key Exchange and Key Encapsulation in the Standard Model

Authenticated Key Exchange and Key Encapsulation in the Standard Model
复制标题

DOI:
10.1007/978-3-540-76900-2_29
复制
发表时间:
2007-12
期刊:
--
影响因子:
--
通讯作者:
T. Okamoto
T. Okamoto
中科院分区:
其他
文献类型:
--
作者:
T. Okamoto

文献摘要

被引文献

相似文献

本文介绍了一种新的范式来实现各种类型的密码原语,如认证密钥交换和密钥封装的标准模型下的三个标准假设:决策Diffie-Hellman(DDH)假设,目标碰撞抵抗(TCR)哈希函数和伪随机函数(PRF)。我们提出了第一个(基于PKI的)两遍认证密钥交换(AKE)协议,该协议与现有的最有效的协议(如MQV)一样有效,并且在标准模型中(在这些标准假设下)是安全的,而现有的高效两遍AKE协议(如HMQV,NAXOS和CMQV)在随机预言模型中是安全的。我们的协议被证明是安全的(目前)最强的安全定义,扩展Canetti-Krawczyk(eCK)安全定义LaMacchia,劳特和Mityagin介绍。本文还提出了一种CCA安全的密钥封装机制(KEM)在这些假设下,这是几乎一样有效的黑泽明KEM。该方案在一个更强的安全概念下也是安全的,即选择公钥和密文攻击(CPCA)安全性。本文中提出的方案是无冗余的(或无有效性检查的),并且其含义是将它们与无冗余对称加密(DEM)组合将产生无冗余的(例如,无MAC)CCA安全混合加密。
This paper introduces a new paradigm to realize various types of cryptographic primitives such as authenticated key exchange and key encapsulation in the standard model under three standard assumptions: the decisional Diffie-Hellman (DDH) assumption, target collision resistant (TCR) hash functions and pseudo-random functions (PRFs). We propose the first (PKI-based) two-pass authenticated key exchange (AKE) protocol that is comparably as efficient as the existing most efficient protocols like MQV and that is secure in the standard model (under these standard assumptions), while the existing efficient two-pass AKE protocols such as HMQV, NAXOS and CMQV are secure in the random oracle model. Our protocol is shown to be secure in the (currently) strongest security definition, the extended Canetti-Krawczyk (eCK) security definition introduced by LaMacchia, Lauter and Mityagin. This paper also proposes a CCA-secure key encapsulation mechanism (KEM) under these assumptions, which is almost as efficient as the Kurosawa-Desmedt KEM. This scheme is also secure in a stronger security notion, the chosen public-key and ciphertext attack (CPCA) security. The proposed schemes in this paper are redundancy-free (or validity-check-free) and the implication is that combining them with redundancy-free symmetric encryption (DEM) will yield redundancy-free (e.g., MAC-free) CCA-secure hybrid encryption.