Data Is a Stream: Security of Stream-Based Channels

Data Is a Stream: Security of Stream-Based Channels
复制标题

DOI:
10.1007/978-3-662-48000-7_27
复制
发表时间:
2015-08
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
M. Fischlin;Felix Günther;G. Marson;K. Paterson
M. Fischlin;Felix Günther;G. Marson;K. Paterson
中科院分区:
其他
文献类型:
--
作者:
M. Fischlin;Felix Günther;G. Marson;K. Paterson

文献摘要

相似文献

文献中定义安全通道的常见方法是考虑通过原子加密和解密接口提供的离散消息的传输。然而,这忽略了许多实用协议(包括 TLS、SSH 和 QUIC)反而提供流接口,而且网络(可能在对抗性控制下)可能会向接收者传送任意密文片段。为了解决这个缺陷,我们启动了基于流的通道及其安全性的研究。我们提出了此类通道的机密性和完整性概念,类似于原子通道的概念,但考虑到了流的特殊性。我们为我们的设置提供了一个合成结果,表明将选择的明文机密性与传输的密文流的完整性相结合可以将通道的机密性提升到选择的密文安全性。值得注意的是,为了在流设置中证明这个定理,我们需要一个额外的属性,称为错误可预测性。我们最终给出了一个基于 AEAD 的构造,实现了我们基于安全流的通道的概念。该结构与 TLS 中使用的结构非常匹配,提供了该协议设计的验证。
The common approach to defining secure channels in the literature is to consider transportation of discrete messages provided via atomic encryption and decryption interfaces. This, however, ignores that many practical protocols (including TLS, SSH, and QUIC) offer streaming interfaces instead, moreover with the complexity that the network (possibly under adversarial control) may deliver arbitrary fragments of ciphertexts to the receiver. To address this deficiency, we initiate the study of stream-based channels and their security. We present notions of confidentiality and integrity for such channels, akin to the notions for atomic channels, but taking the peculiarities of streams into account. We provide a composition result for our setting, saying that combining chosen-plaintext confidentiality with integrity of the transmitted ciphertext stream lifts confidentiality of the channel to chosen-ciphertext security. Notably, for our proof of this theorem in the streaming setting we need an additional property, called error predictability. We finally give an AEAD-based construction that achieves our notion of a secure stream-based channel. The construction matches rather well the one used in TLS, providing validation of that protocol’s design.