Universally Composable End-to-End Secure Messaging

Universally Composable End-to-End Secure Messaging
复制标题

DOI:
10.1007/978-3-031-15979-4_1
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
R. Canetti;Palak Jain;Marika Swanberg;Mayank Varia
R. Canetti;Palak Jain;Marika Swanberg;Mayank Varia
中科院分区:
其他
文献类型:
--
作者:
R. Canetti;Palak Jain;Marika Swanberg;Mayank Varia

文献摘要

相似文献

我们在UC框架内对Signal端到端消息传递协议进行建模和分析。特别是:我们制定了一个理想的功能,捕获端到端的安全消息传递,在设置与PKI和不受信任的服务器,对对手,有完全控制网络,可以自适应和随时妥协各方在任何时候,并获得他们的整个内部状态。特别是,我们的分析捕获了Signal的前向保密和安全恢复属性以及它们被破坏的条件。(PKI和长期密钥,骨干连续密钥交换或“非对称棘轮”,纪元级对称棘轮,认证加密)作为单独的理想功能,分别实现和分析,然后使用UC和Global-状态UC定理。我们展示了如何在最小硬度假设下使用标准密码原语实现代表这些组件的理想功能。我们的建模引入了额外的创新,使人们能够讨论Signal的安全性,而不管底层通信介质如何,以及共享状态的动态生成模块的安全组合。这些功能,再加上UC框架的基本模块化,将有希望促进使用信号作为一个整体,其单独的组件在cryptographicapplication.Two其他功能,我们的建模是完全自适应腐败的治疗,并尽量减少使用随机预言抽象。特别是,我们展示了如何在普通模型中实现连续的密钥交换,同时保持自适应腐败的安全性。
We model and analyze the Signal end-to-end messaging protocol within the UC framework. In particular:We formulate an ideal functionality that captures end-to-end secure messaging, in a setting with PKI and an untrusted server, against an adversary that has full control over the network and can adaptively and momentarily compromise parties at any time and obtain their entire internal states. In particular our analysis captures the forward secrecy and recovery-of-security properties of Signal and the conditions under which they break.We model the main components of the Signal architecture (PKI and long-term keys, the backbone continuous-key-exchange or “asymmetric ratchet,” epoch-level symmetric ratchets, authenticated encryption) as individual ideal functionalities that are realized and analyzed separately and then composed using the UC and Global-State UC theorems.We show how the ideal functionalities representing these components can be realized using standard cryptographic primitives under minimal hardness assumptions.Our modeling introduces additional innovations that enable arguing about the security of Signal irrespective of the underlying communication medium, as well as secure composition of dynamically generated modules that share state. These features, together with the basic modularity of the UC framework, will hopefully facilitate the use of both Signal-as-a-whole and its individual components within cryptographic applications.Two other features of our modeling are the treatment of fully adaptive corruptions, and making minimal use of random oracle abstractions. In particular, we show how to realize continuous key exchange in the plain model, while preserving security against adaptive corruptions.