Multi-instance Security and Its Application to Password-Based Cryptography

Multi-instance Security and Its Application to Password-Based Cryptography
复制标题

多实例安全及其在密码密码学中的应用

DOI:
--
复制
发表时间:
2012
期刊:
Annual International Cryptology Conference
影响因子:
--
通讯作者:
Stefano Tessaro
Stefano Tessaro
中科院分区:
--
文献类型:
--
作者:
M. Bellare;Thomas Ristenpart;Stefano Tessaro

文献摘要

被引文献

相似文献

本文发展了多实例 mi 安全理论,并将其应用于基于密码的密码学中加盐的经典实践,提供第一个基于证明的支持。 Mi-security 在基于密码的加密等设置中发挥作用,在这种设置中,危害单个实例在计算上是可行的,并提供第二道防线,旨在确保在密码情况下,通过加盐,危害所有大量 m 个实例的努力随 m 线性增长。第一个挑战是定义,我们建议 LORX 安全性作为 mi 加密安全性的一个很好的指标,并通过表明它暗示其他自然指标来支持这一主张,说明在这个过程中,即使将简单的结果从 si 设置提升到 mi 也需要新技术。接下来,我们提供一个基于组合的框架,借助密钥派生函数将标准单实例 si 安全性转移到 mi-安全性。根据 PKCS#5 标准分析基于密码的 KDF,以表明它们符合我们对 KDF 的不可微分式 mi-安全性定义,我们能够得出第一个证明,即每个密码盐按照实践中所希望的那样增强了 mi-安全性。我们相信,微安全在其他领域也很有趣,这项工作为其进一步的理论发展和实际应用奠定了基础。
This paper develops a theory of multi-instance mi security and applies it to provide the first proof-based support for the classical practice of salting in password-based cryptography. Mi-security comes into play in settings like password-based cryptography where it is computationally feasible to compromise a single instance, and provides a second line of defense, aiming to ensure in the case of passwords, via salting that the effort to compromise all of some large number m of instances grows linearly with m. The first challenge is definitions, where we suggest LORX-security as a good metric for mi security of encryption and support this claim by showing it implies other natural metrics, illustrating in the process that even lifting simple results from the si setting to the mi one calls for new techniques. Next we provide a composition-based framework to transfer standard single-instance si security to mi-security with the aid of a key-derivation function. Analyzing password-based KDFs from the PKCS#5 standard to show that they meet our indifferentiability-style mi-security definition for KDFs, we are able to conclude with the first proof that per password salts amplify mi-security as hoped in practice. We believe that mi-security is of interest in other domains and that this work provides the foundation for its further theoretical development and practical application.