How to Securely Outsource Cryptographic Computations

How to Securely Outsource Cryptographic Computations
复制标题

DOI:
10.1007/978-3-540-30576-7_15
复制
发表时间:
2005-02
期刊:
影响因子:
3.4
通讯作者:
S. Hohenberger;Anna Lysyanskaya
S. Hohenberger;Anna Lysyanskaya
中科院分区:
化学3区
文献类型:
--
作者:
S. Hohenberger;Anna Lysyanskaya

文献摘要

被引文献

相似文献

我们解决了使用不受信任的(潜在的恶意)加密助手的问题。我们提供了一个正式的安全定义,安全地外包计算从计算有限的设备到一个不可信的助手。在我们的模型中,对抗环境为助手编写软件,但一旦设备开始依赖它,就不会与它直接通信。除了安全性之外,我们还提供了一个框架来量化外包实施的效率和可检查性。我们提出了两个实用的外包安全计划。具体来说,我们将展示如何安全地外包模幂运算,这是计算有限设备上大多数公钥密码术的计算瓶颈。如果没有外包,设备将需要O(n)模乘法来执行n位指数的模幂运算。对于任何基于指数的方案,负载减少到O(log 2n),其中诚实的设备可以使用两个不可信的指数程序;我们强调Cramer-Shoup密码系统[13]和Schnorr签名[28]作为示例。与一个宽松的安全概念,我们实现了相同的负载减少一个新的CCA 2安全的加密方案,只使用一个不可信的Cramer-Shoup加密程序。
We address the problem of using untrusted (potentially malicious) cryptographic helpers. We provide a formal security definition forsecurely outsourcingcomputations from a computationally limited device to an untrusted helper. In our model, the adversarial environment writes the software for the helper, but then does not have direct communication with it once the device starts relying on it. In addition to security, we also provide a framework for quantifying theefficiencyandcheckabilityof an outsourcing implementation. We present two practical outsource-secure schemes. Specifically, we show how to securely outsource modular exponentiation, which presents the computational bottleneck in most public-key cryptography on computationally limited devices. Without outsourcing, a device would needO(n) modular multiplications to carry out modular exponentiation forn-bit exponents. The load reduces toO(log2n) for any exponentiation-based scheme where the honest device may use two untrusted exponentiation programs; we highlight the Cramer-Shoup cryptosystem [13] and Schnorr signatures [28] as examples. With a relaxed notion of security, we achieve the same load reduction for a new CCA2-secure encryption scheme using only one untrusted Cramer-Shoup encryption program.