Breakdown Resilience of Key Exchange Protocols: NewHope, TLS 1.3, and Hybrids

Breakdown Resilience of Key Exchange Protocols: NewHope, TLS 1.3, and Hybrids
复制标题

DOI:
10.1007/978-3-030-29962-0_25
复制
发表时间:
2019-09
期刊:
--
影响因子:
--
通讯作者:
Jacqueline Brendel;M. Fischlin;Felix Günther
Jacqueline Brendel;M. Fischlin;Felix Günther
中科院分区:
其他
文献类型:
--
作者:
Jacqueline Brendel;M. Fischlin;Felix Günther

文献摘要

被引文献

相似文献

损坏的加密算法和硬度假设是对现实世界协议的持续威胁。突出的例子是已知冲突的哈希函数,或者受到量子计算进步威胁的数论假设。特别是在密钥交换协议方面,向抗量子原语的转变已经开始,旨在保护当今的秘密免受未来发展的影响,从常见的基于 Diffie-Hellman 的解决方案转向基于错误学习的方法,通常通过中间混合设计。迄今为止,还没有密钥交换协议的安全概念可以捕获任意加密原语的崩溃场景,以论证先前甚至正在进行和未来会话的安全性。在这项工作中,我们扩展了常见的 Bellare-Rogaway 模型来捕获密钥交换协议的故障恢复能力。我们的扩展模型使我们能够研究协议的安全性,即使在所使用的原语意外失败的情况下,它可能是数论假设、散列函数、签名方案、密钥导出函数等。然后,我们应用我们的安全模型来分析两个现实世界的协议,表明某些原语的故障恢复力是通过后量子安全密钥封装机制的经过验证的变体(Alkim 等人)实现的,该变体是后量子密码学标准化过程中的第二轮候选者NIST 以及 TLS 1.3,最近已被互联网工程任务组标准化为 RFC 8446。
Broken cryptographic algorithms and hardness assumptions are a constant threat to real-world protocols. Prominent examples are hash functions for which collisions become known, or number-theoretic assumptions which are threatened by advances in quantum computing. Especially when it comes to key exchange protocols, the switch to quantum-resistant primitives has begun and aims to protect today’s secrets against future developments, moving from common Diffie–Hellman-based solutions to Learning-With-Errors-based approaches, often via intermediate hybrid designs.To this date there exists no security notion for key exchange protocols that could capture the scenario of breakdowns of arbitrary cryptographic primitives to argue security of prior or even ongoing and future sessions. In this work we extend the common Bellare–Rogaway model to capturebreakdown resilienceof key exchange protocols. Our extended model allows us to study security of a protocol even in case of unexpected failure of employed primitives, may it be number-theoretic assumptions, hash functions, signature schemes, key derivation functions, etc. We then apply our security model to analyze two real-world protocols, showing that breakdown resilience for certain primitives is achieved by both an authenticated variant of the post-quantum secure key encapsulation mechanism(Alkim et al.) which is a second round candidate in the Post Quantum Cryptography standardization process by NIST, as well as by TLS 1.3, which has recently been standardized as RFC 8446 by the Internet Engineering Task Force.