课题基金 / 基金详情

TWC: Medium: Collaborative: The Theory and Practice of Key Derivation

TWC: Medium: Collaborative: The Theory and Practice of Key Derivation
TWC:媒介:协作:密钥派生的理论与实践
批准号:
1314568
负责人:
Yevgeniy Dodis
金额:
$66.88万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-08-01 至 2019-07-31

项目摘要

项目成果

Yevgeniy Dodis的其他基金

相似基金

相关文献

中文摘要
翻译
大多数加密应用程序关键依赖于随机选择的、攻击者未知的密钥。遗憾的是,在实践中推导密钥的过程往往是困难的、容易出错的,并且充满了安全漏洞。尽管复杂的设计和严格的数学分析,但糟糕的生成密钥提供了一个普遍的攻击源,使复杂的密码应用程序完全不安全。尽管密钥派生在安全领域发挥着核心作用,但令人惊讶的是,它在密码界几乎没有得到正式的研究,导致理论和实践之间存在很大的脱节。在本项目中,研究了密钥派生的几个重要场景,以了解它们在可证明保证的情况下提高安全性的能力,包括使用随机数生成器(RNG)、密码和生物测定。具体地说:-RNG如何被设计成适当地组合熵收集、随机性提取和伪随机生成模块,同时针对各种敌对场景实现明确定义的安全属性的可能的最佳子集。-如何降低脱机词典攻击的有效性?从密码生成密钥时。-如何安全地重复使用生物识别技术来在许多应用程序中生成许多密钥,这引发了几个有趣的问题,将密码安全属性与纠错码的安全属性结合在一起。
英文摘要
Most cryptographic applications crucially rely on secret keys that are chosen randomly and are unknown to an attacker. Unfortunately, the process of deriving secret keys in practice is often difficult, error-prone and riddled with security vulnerabilities. Badly generated keys offer a prevalent source of attacks that render complex cryptographic applications completely insecure, despite their sophisticated design and rigorous mathematical analysis. Even though key derivation plays a central role in the security landscape, it has received surprisingly little formal study within the cryptographic community, leading to a large disconnect between the theory and practice. In this project, several important scenarios for key derivation are examined for their capability to improve security with provable guarantees, including the use of random number generators (RNGs), passwords, and biometrics. In particular: - How RNGs are designed to properly combine the entropy gathering, randomness extraction and pseudorandom generation modules, while achieving the best possible subset of clearly defined security properties against a variety of adversarial scenarios. - How to reduce the effectiveness of ?offline dictionary attacks? when generating keys from passwords. - How biometrics can be safely reused to generate many secret keys across many applications raises several interesting questions, combining cryptographic security properties with those of error-correcting codes.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Making Crypto Too BIG To Break
  • 批准号:
    2055578
  • 项目类别:
    Standard Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2021
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
SaTC: CORE: Small: On the Power of Preprocessing and Non-Uniformity
  • 批准号:
    1815546
  • 项目类别:
    Standard Grant
  • 资助金额:
    $38.0万
  • 财政年份:
    2018
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
TWC: Small: On the Design of Secure Hash Functions and Block Ciphers
  • 批准号:
    1619158
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2016
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
TWC: Small: On Imperfect Randomness and Leakage-Resilient Cryptography
  • 批准号:
    1319051
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2013
  • 负责人:
    Yevgeniy Dodis
  • 依托单位:
海外基金