A Framework for Universally Composable Diffie-Hellman Key Exchange

A Framework for Universally Composable Diffie-Hellman Key Exchange
复制标题

DOI:
10.1109/sp.2017.63
复制
发表时间:
2017-05
期刊:
2017 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Ralf Küsters;Daniel Rausch
Ralf Küsters;Daniel Rausch
中科院分区:
其他
文献类型:
--
作者:
Ralf Küsters;Daniel Rausch

文献摘要

相似文献

分析现实世界的协议,特别是密钥交换协议和建立在这些协议上的协议,是一项非常复杂、容易出错和繁琐的任务。除了协议本身的复杂性之外,一个重要的原因是协议的安全性必须一次又一次地降低到每个协议的底层密码原语的安全性。因此,我们希望尽可能多地摆脱现实世界密钥交换协议的归约证明,并且在许多情况下,对于使用交换密钥的更高级别的协议也是如此。到目前为止,已经在这方面采取了一些初步步骤。但是现有的工作仍然非常有限,例如,不支持Diffie-Hellman(DH)密钥交换,这是现实世界协议中普遍存在的加密原语。在本文中,由Küsters和Tuengerthal的工作的基础上,我们提供了一个理想的功能,在通用的可组合性设置,支持几个常见的密码原语,包括DH密钥交换。此功能有助于避免在分析真实世界协议时使用归约证明,并且通常可以完全消除它们。我们还提出了一个新的一般理想的密钥交换功能,它允许更高级别的协议使用交换的密钥在一个理想的方式。作为概念的证明,我们将我们的框架应用到三个实际的DH密钥交换协议,即ISO 9798-3,SIGMA和OPTLS。
The analysis of real-world protocols, in particular key exchange protocols and protocols building on these protocols, is a very complex, error-prone, and tedious task. Besides the complexity of the protocols itself, one important reason for this is that the security of the protocols has to be reduced to the security of the underlying cryptographic primitives for every protocol time and again. We would therefore like to get rid of reduction proofs for real-world key exchange protocols as much as possible and in many cases altogether, also for higher-level protocols which use the exchanged keys. So far some first steps have been taken in this direction. But existing work is still quite limited, and, for example, does not support Diffie-Hellman (DH) key exchange, a prevalent cryptographic primitive for real-world protocols. In this paper, building on work by Küsters and Tuengerthal, we provide an ideal functionality in the universal composability setting which supports several common cryptographic primitives, including DH key exchange. This functionality helps to avoid reduction proofs in the analysis of real-world protocols and often eliminates them completely. We also propose a new general ideal key exchange functionality which allows higher-level protocols to use exchanged keys in an ideal way. As a proof of concept, we apply our framework to three practical DH key exchange protocols, namely ISO 9798-3, SIGMA, and OPTLS.