TWC: Medium: Collaborative: The Theory and Practice of Key Derivation
TWC:媒介:协作:密钥派生的理论与实践
基本信息
- 批准号:1314568
- 负责人:
- 金额:$ 66.88万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2013
- 资助国家:美国
- 起止时间:2013-08-01 至 2019-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Most cryptographic applications crucially rely on secret keys that are chosen randomly and are unknown to an attacker. Unfortunately, the process of deriving secret keys in practice is often difficult, error-prone and riddled with security vulnerabilities. Badly generated keys offer a prevalent source of attacks that render complex cryptographic applications completely insecure, despite their sophisticated design and rigorous mathematical analysis. Even though key derivation plays a central role in the security landscape, it has received surprisingly little formal study within the cryptographic community, leading to a large disconnect between the theory and practice. In this project, several important scenarios for key derivation are examined for their capability to improve security with provable guarantees, including the use of random number generators (RNGs), passwords, and biometrics. In particular: - How RNGs are designed to properly combine the entropy gathering, randomness extraction and pseudorandom generation modules, while achieving the best possible subset of clearly defined security properties against a variety of adversarial scenarios. - How to reduce the effectiveness of ?offline dictionary attacks? when generating keys from passwords. - How biometrics can be safely reused to generate many secret keys across many applications raises several interesting questions, combining cryptographic security properties with those of error-correcting codes.
大多数密码应用程序都依赖于随机选择的密钥,并且攻击者不知道这些密钥。不幸的是,在实践中导出密钥的过程通常是困难的,容易出错的,并且充满了安全漏洞。生成错误的密钥是一种普遍的攻击源,使复杂的加密应用程序完全不安全,尽管它们有复杂的设计和严格的数学分析。 尽管密钥推导在安全领域中起着核心作用,但令人惊讶的是,它在密码学界很少得到正式的研究,导致理论与实践之间存在很大的脱节。在这个项目中,几个重要的场景密钥推导检查他们的能力,以提高安全性与可证明的保证,包括使用随机数生成器(RNG),密码和生物识别。 特别是:- 如何设计RNG以适当地联合收割机组合熵收集、随机性提取和伪随机生成模块,同时针对各种对抗性场景实现明确定义的安全属性的最佳可能子集。- 如何降低功效?离线字典攻击?当从密码生成密钥时。- 如何安全地重复使用生物识别技术来生成许多应用程序中的许多密钥,这提出了几个有趣的问题,将密码学安全属性与纠错码的安全属性相结合。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Yevgeniy Dodis其他文献
Signcryption
- DOI:
10.1007/0-387-23483-7_398 - 发表时间:
2005 - 期刊:
- 影响因子:0
- 作者:
Yevgeniy Dodis - 通讯作者:
Yevgeniy Dodis
Leftover Hash Lemma, Revisited
- DOI:
- 发表时间:
2011 - 期刊:
- 影响因子:
- 作者:
Boaz Barak;Yevgeniy Dodis;Hugo Krawczyk;Olivier Pereira;Krzysztof Pietrzak;Francois-Xavier Standaert;Yu Yu; - 通讯作者:
Yevgeniy Dodis的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Yevgeniy Dodis', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Medium: Making Crypto Too BIG To Break
合作研究:SaTC:核心:媒介:让加密货币变得太大而无法破坏
- 批准号:
2055578 - 财政年份:2021
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
SaTC: CORE: Small: On the Power of Preprocessing and Non-Uniformity
SaTC:核心:小:论预处理和非均匀性的力量
- 批准号:
1815546 - 财政年份:2018
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: Small: On the Design of Secure Hash Functions and Block Ciphers
TWC:小:关于安全散列函数和分组密码的设计
- 批准号:
1619158 - 财政年份:2016
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: Small: On Imperfect Randomness and Leakage-Resilient Cryptography
TWC:小:关于不完美随机性和抗泄漏密码学
- 批准号:
1319051 - 财政年份:2013
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
- 批准号:
1065288 - 财政年份:2011
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TC: Small: The Design of Secure Hash Functions and Block Ciphers
TC:小:安全散列函数和分组密码的设计
- 批准号:
1017471 - 财政年份:2010
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
CT-ISG: On Imperfect Randomness and Exposure-Resilient Cryptography
CT-ISG:关于不完美随机性和暴露弹性密码学
- 批准号:
0831299 - 财政年份:2008
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
Collaborative Research: Rigorous Cryptography from Biometrics and Other Noisy Data
合作研究:来自生物识别和其他噪音数据的严格密码学
- 批准号:
0515121 - 财政年份:2005
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
Collaborative Research: Mitigating the Damaging Effects of Key Exposure
合作研究:减轻关键暴露的破坏性影响
- 批准号:
0311095 - 财政年份:2003
- 资助金额:
$ 66.88万 - 项目类别:
Continuing Grant
CAREER: Exposure-Resilient Cryptography
职业:暴露弹性密码学
- 批准号:
0133806 - 财政年份:2002
- 资助金额:
$ 66.88万 - 项目类别:
Continuing Grant
相似海外基金
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1840790 - 财政年份:2018
- 资助金额:
$ 66.88万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
- 批准号:
1937622 - 财政年份:2018
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
- 批准号:
1855391 - 财政年份:2018
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
- 批准号:
1854000 - 财政年份:2018
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
- 批准号:
1929901 - 财政年份:2018
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
- 批准号:
1801986 - 财政年份:2017
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
- 批准号:
1562888 - 财政年份:2016
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1563848 - 财政年份:2016
- 资助金额:
$ 66.88万 - 项目类别:
Standard Grant