Reactively Simulatable Certified Mail
Reactively Simulatable Certified Mail
复制标题
反应式模拟认证邮件
DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
M. Waidner
中科院分区:
文献类型:
--
作者:
B. Pfitzmann;M. Schunter;M. Waidner
Certified mail is the fair exchange of a message for a receipt, i.e., the recipient gets the message if and only if the sender gets a receipt. It is an mportant primitive for electronic commerce and other atomicity services. Certifie d-mail protocols are known in the literature, but there was no rigorous definition yet, in p articular for optimistic protocols and for many interleaved executions. We provide such a defini tion via an ideal system and show that a specific real certified-mail protocol is as secure as this ideal system in the sense of reactive simulatability in the standard model of cr yptography and under standard assumptions. As certified mail without any third party is not practical, we consider optimistic protocols, which involve a third party only if one party tries to ch eat. The real protocol resembles prior protocols, but we had to use a different cryptographic rimitive to achieve simulatability. The communication model is synchronous. This proof first demonstrated that a cryptographic multi-st ep protocol can fulfil a general definition of reactive simulatability enabling concur rent composition. We also first showed how formal-method style reasoning can be applied ove r the ideal system in a cryptographically sound way. Moreover, the treatment of multip le protocol runs and their modular proof in spite of the use of common cryptographic primit ives for all runs can be seen as a first example of what is now known as joint-state composit ion.