课题基金 / 基金详情

TWC: Medium: Collaborative: The Theory and Practice of Key Derivation

TWC: Medium: Collaborative: The Theory and Practice of Key Derivation
TWC:媒介:协作:密钥派生的理论与实践
批准号:
1314568
负责人:
Yevgeniy Dodis
金额:
$66.88万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-08-01 至 2019-07-31

项目摘要

项目成果

Yevgeniy Dodis的其他基金

相似基金

相关文献

中文摘要
翻译
大多数加密应用程序都依赖于随机选择的、攻击者不知道的密钥。不幸的是,在实践中获取密钥的过程通常很困难,容易出错,并且充满了安全漏洞。尽管复杂的加密应用程序具有复杂的设计和严格的数学分析,但错误生成的密钥提供了一个普遍的攻击来源,使其完全不安全。尽管密钥派生在安全领域发挥着核心作用,但令人惊讶的是,它在密码学社区中得到的正式研究很少,导致理论与实践之间存在很大的脱节。在本项目中,研究了几个重要的密钥派生场景,以了解它们通过可证明的保证提高安全性的能力,包括使用随机数生成器(rng)、密码和生物识别技术。特别是:-如何设计rng以适当地结合熵收集,随机性提取和伪随机生成模块,同时实现针对各种敌对场景的明确定义的安全属性的最佳子集。-如何降低有效性?离线字典攻击?从密码生成密钥时。如何安全地重复使用生物识别技术,以在许多应用程序中生成许多密钥,将加密安全属性与纠错代码相结合,提出了几个有趣的问题。
英文摘要
Most cryptographic applications crucially rely on secret keys that are chosen randomly and are unknown to an attacker. Unfortunately, the process of deriving secret keys in practice is often difficult, error-prone and riddled with security vulnerabilities. Badly generated keys offer a prevalent source of attacks that render complex cryptographic applications completely insecure, despite their sophisticated design and rigorous mathematical analysis. Even though key derivation plays a central role in the security landscape, it has received surprisingly little formal study within the cryptographic community, leading to a large disconnect between the theory and practice. In this project, several important scenarios for key derivation are examined for their capability to improve security with provable guarantees, including the use of random number generators (RNGs), passwords, and biometrics. In particular: - How RNGs are designed to properly combine the entropy gathering, randomness extraction and pseudorandom generation modules, while achieving the best possible subset of clearly defined security properties against a variety of adversarial scenarios. - How to reduce the effectiveness of ?offline dictionary attacks? when generating keys from passwords. - How biometrics can be safely reused to generate many secret keys across many applications raises several interesting questions, combining cryptographic security properties with those of error-correcting codes.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Making Crypto Too BIG To Break
  • 批准号:
    2055578
  • 项目类别:
    Standard Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2021
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
SaTC: CORE: Small: On the Power of Preprocessing and Non-Uniformity
  • 批准号:
    1815546
  • 项目类别:
    Standard Grant
  • 资助金额:
    $38.0万
  • 财政年份:
    2018
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
TWC: Small: On the Design of Secure Hash Functions and Block Ciphers
  • 批准号:
    1619158
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2016
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
TWC: Small: On Imperfect Randomness and Leakage-Resilient Cryptography
  • 批准号:
    1319051
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2013
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
海外基金