A Unified Security Analysis of Two-Phase Key Exchange Protocols in TPM 2.0

A Unified Security Analysis of Two-Phase Key Exchange Protocols in TPM 2.0
复制标题

DOI:
10.1007/978-3-319-22846-4_3
复制
发表时间:
2015-08
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Shijun Zhao;Qianying Zhang
Shijun Zhao;Qianying Zhang
中科院分区:
其他
文献类型:
--
作者:
Shijun Zhao;Qianying Zhang

文献摘要

被引文献

相似文献

可信平台模块 (TPM) 2.0 版通过单个密钥交换原语提供经过身份验证的密钥交换功能,可以调用该功能来实现三种密钥交换协议(在 TPM 2.0 中表示为两阶段密钥交换协议):完全统一模型、MQV 和 SM2 密钥交换协议。然而,所有这些协议中都发现了一些漏洞。幸运的是,TPM 提供的保护似乎可以处理这些协议的漏洞。本文研究了 TPM 密钥交换原语是否在 TPM 的保护下提供安全的密钥交换功能。我们首先对 TPM 密钥交换原语进行非正式分析,这有助于我们以精确的方式进行建模。然后我们在AKE安全模型中正式分析了TPM密钥交换原语,在此基础上可以统一分析TPM 2.0采用的所有协议。我们的分析表明在什么条件下 TPM 2.0 可以提供可证明的安全密钥交换功能。最后,我们提出了如何正确利用TPM密钥交换原语的建议,以及如何提高当前TPM密钥交换原语的安全性以使其在实践中广泛使用的建议。
The Trusted Platform Module (TPM) version 2.0 provides an authenticated key exchange functionality by a single key exchange primitive, which can be called to implement three key exchange protocols (denoted as two-phase key exchange protocols in TPM 2.0): the Full Unified Model, the MQV, and the SM2 key exchange protocols. However, some vulnerabilities have been found in all of these protocols. Fortunately, it seems that protections provided by the TPM can deal with vulnerabilities of these protocols. This paper investigates whether the TPM key exchange primitive provides a secure key exchange functionality under protections of the TPM. We first perform an informal analysis of the TPM key exchange primitive which helps us to model in a precise way. Then we formally analyze the TPM key exchange primitive in a security model for AKE, based on which all the protocols adopted by TPM 2.0 can be analyzed in a unified way. Our analysis indicates under what conditions the TPM 2.0 can provide a provable secure key exchange functionality. In the end, we give suggestions on how to leverage the TPM key exchange primitive properly, and suggestions on how to improve the security of current TPM key exchange primitive to enable its wide use in practice.