How to Securely Outsource Cryptographic Computations
How to Securely Outsource Cryptographic Computations
复制标题
DOI:
10.1007/978-3-540-30576-7_15
复制
发表时间:
2005-02
期刊:
影响因子:
3.4
通讯作者:
S. Hohenberger;Anna Lysyanskaya
中科院分区:
文献类型:
--
作者:
S. Hohenberger;Anna Lysyanskaya
We address the problem of using untrusted (potentially malicious) cryptographic helpers. We provide a formal security definition forsecurely outsourcingcomputations from a computationally limited device to an untrusted helper. In our model, the adversarial environment writes the software for the helper, but then does not have direct communication with it once the device starts relying on it. In addition to security, we also provide a framework for quantifying theefficiencyandcheckabilityof an outsourcing implementation. We present two practical outsource-secure schemes. Specifically, we show how to securely outsource modular exponentiation, which presents the computational bottleneck in most public-key cryptography on computationally limited devices. Without outsourcing, a device would needO(n) modular multiplications to carry out modular exponentiation forn-bit exponents. The load reduces toO(log2n) for any exponentiation-based scheme where the honest device may use two untrusted exponentiation programs; we highlight the Cramer-Shoup cryptosystem [13] and Schnorr signatures [28] as examples. With a relaxed notion of security, we achieve the same load reduction for a new CCA2-secure encryption scheme using only one untrusted Cramer-Shoup encryption program.