Universally Composable Authentication and Key-Exchange with Global PKI
Universally Composable Authentication and Key-Exchange with Global PKI
复制标题
通用可组合身份验证和与全球 PKI 的密钥交换
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Margarita Vald
中科院分区:
文献类型:
--
作者:
R. Canetti;Daniel Shahaf;Margarita Vald
Message authentication and key exchange are two of the most basic tasks of cryptography and are often basic components in complex and security-sensitive protocols. Thus composable security analysis of these primitives is highly motivated. Still, the state of the art in composable security analysis of these primitives is somewhat unsatisfactory in the prevalent case where solutions are based on public-key infrastructure PKI. Specifically, existing treatments either ai¾?make the unrealistic assumption that the PKI is accessible only within the confines of the protocol itself, thus failing to capture real-world PKI-based authentication, or bi¾?impose often-unnecessary requirements--such as strong on-line non-transferability--on candidate protocols, thus ruling out natural candidates.
We give a modular and universally composable analytical framework for PKI-based message authentication and key exchange protocols. This framework guarantees security even when the PKI is pre-existing and globally available, without being unnecessarily restrictive. Specifically, we model PKI as a global set-up functionality within the Globali¾?UC security model [Canetti eti¾?al., TCC 2007] and relax the ideal authentication and key exchange functionalities accordingly. We then demonstrate the security of basic signature-based authentication and key exchange protocols. Our modeling makes minimal security assumptions on the PKI in use; in particular, "knowledge of the secret key" is not needed. Furthermore, there is no requirement of uniqueness in this binding: an identity may be represented by multiple strings of public keys.