Reactively Simulatable Certified Mail

Reactively Simulatable Certified Mail
复制标题

反应式模拟认证邮件

DOI:
--
复制
发表时间:
2006
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
M. Waidner
M. Waidner
中科院分区:
--
文献类型:
--
作者:
B. Pfitzmann;M. Schunter;M. Waidner

文献摘要

被引文献

相似文献

认证邮件是公平的消息交换收据,即,当且仅当发送者获得收据时,接收者才获得消息。它是电子商务和其他原子性服务的重要原语。认证邮件协议在文献中是已知的,但还没有严格的定义,特别是乐观协议和许多交错执行。我们通过一个理想的系统提供这样一个定义,并表明一个特定的真实的认证邮件协议是安全的,因为这个理想的系统在这个意义上的反应式模拟的标准模型和标准的假设。由于没有任何第三方的认证邮件是不实际的,我们考虑乐观协议,它只涉及第三方,如果一方试图吃。真实的协议类似于以前的协议,但我们必须使用不同的加密算法来实现可模拟性。通信模型是同步的。该证明首次证明了密码多阶段协议可以满足反应式可模拟性的一般定义,从而实现并发合成。我们还首次展示了形式方法风格的推理如何以加密的方式应用于理想系统。此外,多协议运行的处理及其模块化证明,尽管对所有运行使用共同的密码本原伊韦斯,可以被视为现在称为联合状态通信的第一个例子。
Certified mail is the fair exchange of a message for a receipt, i.e., the recipient gets the message if and only if the sender gets a receipt. It is an mportant primitive for electronic commerce and other atomicity services. Certifie d-mail protocols are known in the literature, but there was no rigorous definition yet, in p articular for optimistic protocols and for many interleaved executions. We provide such a defini tion via an ideal system and show that a specific real certified-mail protocol is as secure as this ideal system in the sense of reactive simulatability in the standard model of cr yptography and under standard assumptions. As certified mail without any third party is not practical, we consider optimistic protocols, which involve a third party only if one party tries to ch eat. The real protocol resembles prior protocols, but we had to use a different cryptographic rimitive to achieve simulatability. The communication model is synchronous. This proof first demonstrated that a cryptographic multi-st ep protocol can fulfil a general definition of reactive simulatability enabling concur rent composition. We also first showed how formal-method style reasoning can be applied ove r the ideal system in a cryptographically sound way. Moreover, the treatment of multip le protocol runs and their modular proof in spite of the use of common cryptographic primit ives for all runs can be seen as a first example of what is now known as joint-state composit ion.