Security of Streaming Encryption in Google's Tink Library

Security of Streaming Encryption in Google's Tink Library
复制标题

DOI:
10.1145/3372297.3417273
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
V. Hoang;Yaobin Shen
V. Hoang;Yaobin Shen
中科院分区:
其他
文献类型:
--
作者:
V. Hoang;Yaobin Shen

文献摘要

相似文献

我们分析了多用户安全的流媒体加密在谷歌的Tink库通过Hoang等人的基于随机数的在线认证加密的框架的扩展版本。(NIPPTO '15),以支持随机访问解密。我们表明,廷克的设计选择使用随机随机数和基于随机数的密钥推导函数确实提高了具体的安全界限。然后,我们给出了两个更好的替代方案,对随机性故障更强大。此外,我们展示了如何通过AES有效地实例化密钥推导函数,而不是像Tink中当前的设计那样依赖于HMAC-SHA 256。为了实现这一点,我们给出了一个多用户分析的异或排列构造的Bellare,Krovetz,和Rogaway(EUROWALPT '98)。
We analyze the multi-user security of the streaming encryption in Google's Tink library via an extended version of the framework of nonce-based online authenticated encryption of Hoang et al. (CRYPTO'15) to support random-access decryption. We show that Tink's design choice of using random nonces and a nonce-based key-derivation function indeed improves the concrete security bound. We then give two better alternatives that are more robust against randomness failure. In addition, we show how to efficiently instantiate the key-derivation function via AES, instead of relying on HMAC-SHA256 like the current design in Tink. To accomplish this we give a multi-user analysis of the XOR-of-permutation construction of Bellare, Krovetz, and Rogaway (EUROCRYPT'98).