Delegation of cryptographic servers for capture-resilient devices

Delegation of cryptographic servers for capture-resilient devices
复制标题

为捕获弹性设备委派加密服务器

DOI:
10.1007/s00446-003-0098-4
复制
发表时间:
2001
影响因子:
1.3
通讯作者:
M. Reiter
M. Reiter
中科院分区:
计算机科学3区
文献类型:
--
作者:
P. MacKenzie;M. Reiter

文献摘要

被引文献

相似文献

执行私钥操作(签名或解密)并且其私钥操作受密码保护的设备可以在捕获的情况下通过强制设备与指定的远程服务器确认密码猜测以执行私钥操作而免受离线字典攻击。最近提出的实现这一点的建议允许不受信任的服务器,并且不需要每个设备的服务器初始化。在本文中,我们扩展了这些建议,使动态委托从一个服务器到另一个;即,该设备随后可以使用第二服务器来保护其私钥操作。一种应用是允许正在国外旅行的用户将确认密码猜测并帮助用户的设备执行私钥操作的能力临时委托给该国家本地的服务器,或者在限制下,将该能力临时委托给用户拥有的令牌。另一个应用是设备私钥的主动安全性,即,对设备和服务器进行主动更新,以消除由于先前受损的服务器而导致的离线密码猜测攻击的任何威胁。
Abstract.A device that performs private key operations (signatures or decryptions), and whose private key operations are protected by a password, can be immunized against offline dictionary attacks in case of capture by forcing the device to confirm a password guess with a designated remote server in order to perform a private key operation. Recent proposals for achieving this allow untrusted servers and require no server initialization per device. In this paper we extend these proposals to enable dynamic delegation from one server to another; i.e., the device can subsequently use the second server to secure its private key operations. One application is to allow a user who is traveling to a foreign country to temporarily delegate to a server local to that country the ability to confirm password guesses and aid the user’s device in performing private key operations, or in the limit, to temporarily delegate this ability to a token in the user’s possession. Another application is proactive security for the device’s private key, i.e., proactive updates to the device and servers to eliminate any threat of offline password guessing attacks due to previously compromised servers.