Security and composition of cryptographic protocols: a tutorial (part I)

Security and composition of cryptographic protocols: a tutorial (part I)
复制标题

DOI:
10.1145/1165555.1165570
复制
发表时间:
2006-09
期刊:
--
影响因子:
--
通讯作者:
R. Canetti
R. Canetti
中科院分区:
其他
文献类型:
--
作者:
R. Canetti

文献摘要

被引文献

相似文献

密码协议“安全”意味着什么?以一种有意义的方式捕获加密任务的安全需求是一件棘手的事情:一方面,我们希望安全标准能够防止对协议的“所有潜在攻击”;另一方面,我们希望我们的标准不要过于严格,并接受“合理的协议”。缺陷的主要原因之一是在复合系统中并行运行的不同协议实例之间经常发生意外的交互。本教程研究了定义加密协议安全性的一般方法。该方法通常被称为“可信方范式”,允许以统一和自然的方式定义各种加密任务的安全要求。我们首先回顾更基本的配方,捕捉安全隔离从其他协议实例。接下来,我们将解决与协议组合相关的安全问题,并审查即使在复合系统中也能保证安全的配方。
What does it mean for a cryptographic protocol to be "secure"? Capturing the security requirements of cryptographic tasks in a meaningful way is a slippery business: On the one hand, we want security criteria that prevent "all potential attacks" against a protocol; on the other hand, we want our criteria not to be overly restrictive and accept "reasonable protocols". One of the main reasons for flaws is the often unexpected interactions among different protocol instances that run alongside each other in a composite system.This tutorial studies a general methodology for defining security of cryptographic protocols. The methodology, often dubbed the "trusted party paradigm", allows for defining the security requirements of a large variety of cryptographic tasks in a unified and natural way. We first review more basic formulations that capture security in isolation from other protocol instances. Next we address the security problems associated with protocol composition, and review formulations that guarantee security even in composite systems.