Cryptanalysis and protocol failures

Cryptanalysis and protocol failures
复制标题

密码分析和协议失败

DOI:
10.1145/188280.188298
复制
发表时间:
1994
期刊:
Commun. ACM
影响因子:
--
通讯作者:
G. J. Simmons
G. J. Simmons
中科院分区:
--
文献类型:
--
作者:
G. J. Simmons

文献摘要

被引文献

相似文献

56 November 1994/Vol.37,No.11 со р а н т а н т н н а р а н т а н т а н о р о с т а н о в о с ти н а信息完整性协议关键地依赖于一个或多个密码或类似密码的操作,以拒绝未经授权地访问或使用协议旨在确保其完整性的信息。显然,如果底层的密码算法被破坏,那么协议的预期功能就可能被破坏。然而,不明显的是,协议设计者或用户经常感到震惊的是,协议可以完全颠覆,而不会质疑甚至侵蚀底层密码算法的安全性。例如,密钥分发协议将密钥分发给非预期的接收者,保密协议公开披露(据称)秘密通信的内容,数字签名协议使伪造变得容易,所有这些协议都基于目前已知的合理的密码算法。至少有一种情况涉及Vernam加密/解密,众所周知,当与正确选择的一次性密钥一起使用时,它是无条件安全的[4];尽管如此,该协议完全失败。这种戏剧性的失败被称为协议失败。当然,在许多协议中,加密部分的安全性由于协议被执行而逐渐减弱--比如说,通过减小必须搜索以识别活动加密密钥的密钥空间的大小--但这些不被认为是真正协议失败的例子,即使它们是协议的预期安全功能中的潜在故障源的明显示例。发现和修复后一种类型的故障是传统的密码算法分析的功能。然而,真正的协议失败,因为它们不是密码算法中的弱点的结果,需要完全不同类型的分析-一种对协议本身的密码分析。本文的目的是双重的:首先提出一些令人信服的例子,现实世界中的协议失败,然后使用这些例子来激发讨论的一般原则的密码分析的协议。
56 November 1994/Vol. 37, No. 11 сомам шмпелтиана, он тнн Ӑем ost information integrity protocols depend crucially on one or more cryptographic or cryptolike operations to deny unauthorized access to or use of information whose integrity the protocol is intended to ensure. Obviously, if the underlying cryptoalgorithm were broken, then the intended function of the protocol could be subverted. What is not obvious, however, and indeed often comes as a shock to the protocol designer or user, is that a protocol can be completely subverted without impeaching, or even eroding, the security of the underlying cryptoalgorithm. There are examples of key distribution protocols that distrib-ute keys to unintended recipients, secrecy protocols that pub-licly reveal the contents of (supposedly) secret communica-tions, digital signature protocols that make forgery easy-all based on cryptoalgorithms that are sound so far as is known. At least one case involves Vernam encryption/decryption, which when used with a properly chosen one-time key is well known to be unconditionally secure [4]; in spite of this the protocol fails totally. A failure of this dramatic type is said to be a protocol failure. In many protocols, of course, the security of the cryptographic portion is progressively weakened as a result of the protocol being exercised–say, by reducing the size of the key space that one would have to search to identify an active cryptographic key—but these are not considered examples of true protocol failures, even though they are clearly examples of potential sources of failure in the intended security function (s) of a protocol. Finding and fixing failures of the latter type is the function of conventional analysis of cryptoalgorithms. True protocol failures, however, since they are not a consequence of weaknesses in the cryptoalgorithm, require an entirely different type of analysis—a type of cryptanalysis of the protocol itself. The purpose of this article is twofold: first to present some convincing examples of real-world protocol failures and then to use these examples to motivate a discussion of general principles for the cryptanalysis of protocols.