How to leak on key updates

How to leak on key updates
复制标题

DOI:
10.1145/1993636.1993732
复制
发表时间:
2011-06
影响因子:
16.2
通讯作者:
Allison Bishop;Mark Lewko;Brent Waters
Allison Bishop;Mark Lewko;Brent Waters
中科院分区:
医学1区
文献类型:
--
作者:
Allison Bishop;Mark Lewko;Brent Waters

文献摘要

被引文献

相似文献

在连续内存泄漏模型中,通过周期性地更新密钥来实现对攻击者的攻击。这是一个吸引人的模型,它捕获了广泛的侧信道攻击,但该模型中的所有以前的构造在密钥更新期间只提供了非常小的泄漏容限。由于密钥更新可能频繁发生,因此提高针对在这些更新期间获得泄漏的攻击者的安全保证是一个重要的问题。在这项工作中,我们提出了第一个加密原语,这是安全的,对超对数的泄漏量在密钥更新。我们目前的签名和公钥加密方案的标准模型,可以容忍一个恒定的分数的秘密密钥被泄露之间的更新,以及一个恒定的分数的秘密密钥和更新的随机性被泄露在更新过程中。我们的签名方案还允许我们在签名过程中泄漏整个秘密状态的恒定部分。在这项工作之前,即使在随机预言模型中,也不知道如何在更新期间容忍超对数泄漏。我们依赖于复合阶双线性群的子群决策假设。
In the continual memory leakage model, security against attackers who can repeatedly obtain leakage is achieved by periodically updating the secret key. This is an appealing model which captures a wide class of side-channel attacks, but all previous constructions in this model provide only a very minimal amount of leakage tolerance during secret key updates. Since key updates may happen frequently, improving security guarantees against attackers who obtain leakage during these updates is an important problem. In this work, we present the first cryptographic primitives which are secure against a super-logarithmic amount of leakage during secret key updates. We present signature and public key encryption schemes in the standard model which can tolerate a constant fraction of the secret key to be leaked between updates as well as a constant fraction of the secret key and update randomness to be leaked during updates. Our signature scheme also allows us to leak a constant fraction of the entire secret state during signing. Before this work, it was unknown how to tolerate super-logarithmic leakage during updates even in the random oracle model. We rely on subgroup decision assumptions in composite order bilinear groups.