Secure Channels Based on Authenticated Encryption Schemes: A Simple Characterization

Secure Channels Based on Authenticated Encryption Schemes: A Simple Characterization
复制标题

基于认证加密方案的安全通道:简单表征

DOI:
--
复制
发表时间:
2002
期刊:
International Conference on the Theory and Application of Cryptology and Information Security
影响因子:
--
通讯作者:
C. Namprempre
C. Namprempre
中科院分区:
--
文献类型:
--
作者:
C. Namprempre

文献摘要

被引文献

相似文献

我们考虑这样的通信会话:一对当事方首先运行经过身份验证的密钥交换协议以获得共享的会话密钥,然后通过基于会话密钥的经过身份验证的加密方案保护它们之间的连续数据传输。我们证明这样的通信会话满足Canetti和Krawczyk[9]提出的安全通道协议的概念,当且仅当底层认证加密方案满足我们引入的两个新的、简单的安全定义,并且密钥交换协议是安全的。换句话说,我们减少了Canetti和Krawczyk的安全通道需求,使其在底层经过身份验证的加密方案上更易于使用、独立的安全需求。此外,我们将这两个新概念与现有的认证加密方案的安全概念联系起来。
We consider communication sessions in which a pair of parties begin by running an authenticated key-exchange protocol to obtain a shared session key, and then secure successive data transmissions between them via an authenticated encryption scheme based on the session key. We show that such a communication session meets the notion of a secure channel protocol proposed by Canetti and Krawczyk [9] if and only if the underlying authenticated encryption scheme meets two new, simple definitions of security that we introduce, and the key-exchange protocol is secure. In other words, we reduce the secure channel requirements of Canetti and Krawczyk to easier to use, stand-alone security requirements on the underlying authenticated encryption scheme. In addition, we relate the two new notions to existing security notions for authenticated encryption schemes.