Threshold schemes for cryptographic primitives:

Threshold schemes for cryptographic primitives:
复制标题

DOI:
10.6028/nist.ir.8214
复制
发表时间:
2019-03
期刊:
--
影响因子:
--
通讯作者:
L. Brandao;N. Mouha;Apostol T. Vassilev
L. Brandao;N. Mouha;Apostol T. Vassilev
中科院分区:
其他
文献类型:
--
作者:
L. Brandao;N. Mouha;Apostol T. Vassilev

文献摘要

被引文献

相似文献

国家标准与技术研究所的计算机安全司对促进实现加密原语的安全性感兴趣。这种安全性不仅取决于原语的理论属性,还取决于抵御对其实现的攻击的能力。因此,重要的是减轻由于密码算法的理想实现和实际实现之间的差异而导致的故障。该文献概述了使用门限方案来实现密码原语的可能性,其中多个组件以即使其n个组件中的f个组件受到危害的方式来实现所需的安全目标的方式对操作作出贡献。在提供对旁路攻击的抵抗力方面也存在已确定的潜力,旁路攻击利用实际实现中的无意泄漏。重要的安全目标包括加密密钥的保密性,以及增强的完整性和可用性等。本文讨论了与密码原语门限方案标准化相关的挑战和机遇。它包括一些示例,说明了在系统模型和对手的变化下的安全权衡。它列举了阈值方案的几个高级特征,包括阈值的类型、(与环境和组件之间的)通信接口、执行平台(例如,单个设备对多个设备)以及设置和维护要求。该文件提出了一些问题,促使在考虑标准化时考虑到一些方面。一个特别的挑战是制定标准,以帮助指导门限加密方案的选择。一个悬而未决的问题是决定每个标准应该定义在什么级别(例如,具体的基本技术与概念化的功能),以及它们应该允许什么样的参数化灵活性。对实现进行测试和验证的适宜性也是需要解决的主要问题。总体而言,该文件旨在支持关于标准化的讨论,包括激励利益相关者的参与。这是朝着在美国联邦政府内外启用门槛加密迈出的一步。
The Computer Security Division at the National Institute of Standards and Technology is interested in promoting the security of implementations of cryptographic primitives. This security depends not only on the theoretical properties of the primitives but also on the ability to withstand attacks on their implementations. It is thus important to mitigate breakdowns that result from differences between ideal and real implementations of cryptographic algorithms. This document overviews the possibility of implementing cryptographic primitives using threshold schemes, where multiple components contribute to the operation in a way that attains the desired security goals even if f out of n of its components are compromised. There is also an identified potential in providing resistance against side-channel attacks, which exploit inadvertent leakage from real implementations. Security goals of interest include the secrecy of cryptographic keys, as well as enhanced integrity and availability, among others. This document considers challenges and opportunities related to standardization of threshold schemes for cryptographic primitives. It includes examples illustrating security tradeoffs under variations of system model and adversaries. It enumerates several high-level characterizing features of threshold schemes, including the types of threshold, the communication interfaces (with the environment and between components), the executing platform (e.g., single device vs. multiple devices) and the setup and maintenance requirements. The document poses a number of questions, motivating aspects to take into account when considering standardization. A particular challenge is the development of criteria that may help guide a selection of threshold cryptographic schemes. An open question is deciding at what level each standard should be defined (e.g., specific base techniques vs. conceptualized functionalities) and which flexibility of parametrization they should allow. Suitability to testing and validation of implementations are also major concerns to be addressed. Overall, the document intends to support discussion about standardization, including motivating an engagement from stakeholders. This is a step towards enabling threshold cryptography within the US federal government and beyond.