Multi-Stage Key Exchange and the Case of Google's QUIC Protocol

Multi-Stage Key Exchange and the Case of Google's QUIC Protocol
复制标题

DOI:
10.1145/2660267.2660308
复制
发表时间:
2014-11
期刊:
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
M. Fischlin;Felix Günther
M. Fischlin;Felix Günther
中科院分区:
其他
文献类型:
--
作者:
M. Fischlin;Felix Günther

文献摘要

被引文献

相似文献

建立安全连接的传统方法是运行密钥交换协议,并且一旦建立了密钥,就在安全通道协议中使用该密钥。密钥交换和信道协议的安全性,以及在某种程度上两者的组成,在文献中已经得到了广泛的研究。然而,这种方法通常福尔斯缺乏捕获一些密钥交换协议,其中,由于实际动机,最初分离的阶段变得交织在一起,并且密钥被连续地建立。此类协议的两个突出例子是TLS(带恢复)和Google最近提出的低延迟协议QUIC。在这项工作中,我们回顾了以前的安全模型Brzuska等。(CCS'11),并将其扩展到Bellare和Rogaway的风格的多阶段密钥交换模型。在我们的模型中,各方可以在不同阶段建立多个密钥,并在阶段之间使用这些密钥,甚至建立下一个密钥。使用Brzuska等人的形式化的优点是,它的设计目的是提供组合保证。因此,我们也可以给出充分条件,在此条件下,多级密钥交换协议与任何安全密钥应用协议(如安全信道协议)安全地组合。然后,我们将模型用于QUIC协议的情况。基本上,我们表明,QUIC是一个足够安全的多阶段密钥交换协议,并满足设计者建议的安全属性。我们继续提出一些轻微的变化,QUIC,使其更适合我们的组合结果,并允许推理其安全性作为一个组合的连接建立协议时,组成一个安全的通道协议。
The traditional approach to build a secure connection is to run a key exchange protocol and, once the key has been established, to use this key afterwards in a secure channel protocol. The security of key exchange and channel protocols, and to some extent also of the composition of both, has been scrutinized extensively in the literature. However, this approach usually falls short of capturing some key exchange protocols in which, due to practical motivation, the originally separated phases become intertwined and keys are established continuously. Two prominent examples of such protocols are TLS (with resumption), and Google's recently proposed low-latency protocol QUIC. In this work we revisit the previous security of model of Brzuska et al. (CCS'11) and expand it into a multi-stage key exchange model in the style of Bellare and Rogaway. In our model, parties can establish multiple keys in different stages and use these keys between stages, even to establish the next key. The advantage of using the formalization of Brzuska et al. is that it has been designed with the aim to provide compositional guarantees. Hence, we can, too, give sufficient conditions under which multi-stage key exchange protocols compose securely with any symmetric-key application protocol, like a secure channel protocol. We then exercise our model for the case of the QUIC protocol. Basically, we show that QUIC is an adequately secure multi-stage key exchange protocol and meets the suggested security properties of the designers. We continue by proposing some slight changes to QUIC to make it more amenable to our composition result and to allow reasoning about its security as a combined connection establishment protocol when composed with a secure channel protocol.