Universally Composable Authentication and Key-Exchange with Global PKI

Universally Composable Authentication and Key-Exchange with Global PKI
复制标题

通用可组合身份验证和与全球 PKI 的密钥交换

DOI:
--
复制
发表时间:
2016
期刊:
International Conference on Theory and Practice of Public Key Cryptography
影响因子:
--
通讯作者:
Margarita Vald
Margarita Vald
中科院分区:
--
文献类型:
--
作者:
R. Canetti;Daniel Shahaf;Margarita Vald

文献摘要

被引文献

相似文献

消息认证和密钥交换是密码学的两个最基本的任务,并且通常是复杂且安全敏感的协议中的基本组成部分。因此,对这些原语的可组合安全分析是非常有动力的。尽管如此,在解决方案基于公钥基础设施 PKI 的普遍情况下,这些原语的可组合安全分析的最新技术还是有些不能令人满意。具体来说,现有的处理方法要么做出不切实际的假设,即 PKI 只能在协议本身的范围内访问,从而无法捕获现实世界中基于 PKI 的身份验证,要么对候选协议强加通常不必要的要求(例如强大的在线不可转移性),从而排除自然候选协议。 我们为基于 PKI 的消息认证和密钥交换协议提供了一个模块化且通用可组合的分析框架。即使 PKI 预先存在且全局可用,该框架也能保证安全,而不会受到不必要的限制。具体来说,我们将 PKI 建模为 GlobaliUC 安全模型 [Canetti 等人,TCC 2007] 中的全局设置功能,并相应地放宽了理想的身份验证和密钥交换功能。然后,我们演示基于签名的基本身份验证和密钥交换协议的安全性。我们的建模对使用中的 PKI 做出了最低限度的安全假设;特别是,不需要“知道密钥”。此外,此绑定不要求唯一性:一个身份可以由多个公钥字符串表示。
Message authentication and key exchange are two of the most basic tasks of cryptography and are often basic components in complex and security-sensitive protocols. Thus composable security analysis of these primitives is highly motivated. Still, the state of the art in composable security analysis of these primitives is somewhat unsatisfactory in the prevalent case where solutions are based on public-key infrastructure PKI. Specifically, existing treatments either ai¾?make the unrealistic assumption that the PKI is accessible only within the confines of the protocol itself, thus failing to capture real-world PKI-based authentication, or bi¾?impose often-unnecessary requirements--such as strong on-line non-transferability--on candidate protocols, thus ruling out natural candidates. We give a modular and universally composable analytical framework for PKI-based message authentication and key exchange protocols. This framework guarantees security even when the PKI is pre-existing and globally available, without being unnecessarily restrictive. Specifically, we model PKI as a global set-up functionality within the Globali¾?UC security model [Canetti eti¾?al., TCC 2007] and relax the ideal authentication and key exchange functionalities accordingly. We then demonstrate the security of basic signature-based authentication and key exchange protocols. Our modeling makes minimal security assumptions on the PKI in use; in particular, "knowledge of the secret key" is not needed. Furthermore, there is no requirement of uniqueness in this binding: an identity may be represented by multiple strings of public keys.