Determining the Core Primitive for Optimally Secure Ratcheting

Determining the Core Primitive for Optimally Secure Ratcheting
复制标题

确定最佳安全棘轮的核心原语

DOI:
10.1007/978-3-030-64840-4_21
复制
发表时间:
2020
期刊:
ArXiv
影响因子:
--
通讯作者:
S. Vaudenay
S. Vaudenay
中科院分区:
--
文献类型:
--
作者:
Fatih Balli;Paul Rösler;S. Vaudenay

文献摘要

被引文献

相似文献

。在棘轮主要由于实际的现实世界协议而引起关注之后,最近有一系列工作从理论的角度将棘轮作为一个原语来研究。这一行的文献追求人们所希望的最强的棘轮安全性,用于构造强大但低效的键更新原语——基于分层身份加密(HIBE)。由于这些作品都没有正式证明使用这些构建模块是合理的,我们回答了一个尚未解决的问题,即它们的使用是否真的是必要的。我们重新审视棘轮密钥交换(RKE)的这些强大概念,并提出一个更现实(也稍微更强大)的安全定义。在这个安全定义中,通信双方的本地状态的暴露和对手攻击执行随机性的能力都被考虑在内。虽然这两种攻击在之前的工作中被部分考虑过,但我们是第一个将它们清晰地统一在一个自然的基于游戏的概念中。我们的定义基于Poettering和Rösler (CRYPTO 2018)的系统RKE概念。由于针对随机性攻击的轻微(但有意义的)更改,我们最终能够证明,为了实现RKE的强大安全性,具有(独立)可更新密钥对的公钥加密是必要的构建块。令人惊讶的是,这种含义已经适用于最简单的RKE变体(以前仅使用标准公钥加密进行实例化)。我们的贡献
. After ratcheting attracted attention mostly due to practical real-world protocols, recently a line of work studied ratcheting as a primitive from a theoretic point of view. Literature in this line, pursuing the strongest security of ratcheting one can hope for, utilized for constructions strong, yet inefficient key-updatable primitives – based on hierarchical identity based encryption (HIBE). As none of these works formally justified utilizing these building blocks, we answer the yet open question whether their use is actually necessary . We revisit these strong notions of ratcheted key exchange (RKE), and propose a more realistic (and slightly stronger) security definition. In this security definition, both the exposure of the communicating parties’ local states and the adversary’s ability to attack the executions’ randomness are considered. While these two attacks were partially considered in previous work, we are the first to unify them cleanly in a natural game based notion. Our definitions are based on the systematic RKE notion by Poettering and Rösler (CRYPTO 2018). Due to slight (but meaningful) changes to regard attacks against randomness, we are ultimately able to show that, in order to fulfill strong security for RKE, public key cryptography with (independently) updatable key pairs is a necessary building block. Surprisingly, this implication already holds for the simplest RKE variant (which was previously instantiated with only standard public key cryptography). Our contributions