The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce Randomization

The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce Randomization
复制标题

DOI:
10.1145/3243734.3243816
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
V. Hoang;Stefano Tessaro;Aishwarya Thiruvengadam
V. Hoang;Stefano Tessaro;Aishwarya Thiruvengadam
中科院分区:
其他
文献类型:
--
作者:
V. Hoang;Stefano Tessaro;Aishwarya Thiruvengadam

文献摘要

被引文献

相似文献

多用户(mu)安全考虑大规模攻击者(例如,国家行为者),获得进入一些会议,试图破坏至少其中之一。在TLS 1.3的开发中明确考虑了认证加密(AE)的Mu安全性。本文重新审视了Mu安全的GCM,这仍然是迄今为止最广泛使用的专用AE模式。我们提供了新的具体的安全界限,通过采用对抗资源的精细参数化来改进以前的工作,该参数化突出了(1)用户之间的随机数重用和(2)密钥更新对安全性的影响。作为主要应用之一,我们给出了TLS 1.3记录协议中采用的随机数随机化机制的严格安全界限,以减轻大规模多用户攻击。我们提供了严格的安全界限,产生第一次验证这种方法。特别是,我们解决了Bellare和Tackmann(NIPPTO '16)的主要开放问题,他们只考虑了不试图违反完整性的受限攻击者,并且只给出了非紧边界。
Multi-user (mu) security considers large-scale attackers (e.g., state actors) that given access to a number of sessions, attempt to compromise at least one of them. Mu security of authenticated encryption (AE) was explicitly considered in the development of TLS 1.3. This paper revisits the mu security of GCM, which remains to date the most widely used dedicated AE mode. We provide new concrete security bounds which improve upon previous work by adopting a refined parameterization of adversarial resources that highlights the impact on security of (1) nonce re-use across users and of (2) re-keying. As one of the main applications, we give tight security bounds for the nonce-randomization mechanism adopted in the record protocol of TLS 1.3 as a mitigation of large-scale multi-user attacks. We provide tight security bounds that yield the first validation of this method. In particular, we solve the main open question of Bellare and Tackmann (CRYPTO '16), who only considered restricted attackers which do not attempt to violate integrity, and only gave non-tight bounds.