课题基金 / 基金详情

TWC: Small: Self-Recovering Certificate Authorities using Backward and Forward Secure Key Management

TWC: Small: Self-Recovering Certificate Authorities using Backward and Forward Secure Key Management
TWC:小型:使用后向和前向安全密钥管理的自恢复证书颁发机构
批准号:
1617774
负责人:
John Chandy
金额:
$32.72万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2021-08-31

项目摘要

项目成果

John Chandy的其他基金

相似基金

相关文献

中文摘要
翻译
近年来已经显示出证书颁发机构(CA)的谬误;内部人员能够窃取主签名密钥并冒充证书,利用系统漏洞和其他渗透手段允许攻击者访问CA并复制他们的密钥等。危急关头仅仅是公钥基础设施的生存,因为对它们的信任是从对将公钥绑定到已知身份的证书的信任中引导的。CA目前暴露的攻击面使人们对其颁发的证书的信任受到质疑。主要问题是当前被盗的密钥泄露了有关将来用于签名未来证书的密钥的信息。该项目引入了一种新的后向安全概念,允许CA撤销新重建的密钥,这些密钥被攻击者恶意修改,甚至在攻击者能够签署有效证书之前就为攻击者所知。该项目还提供了有效的自我恢复,这意味着在强大的对手在场的情况下,CA能够用新的未泄露的签名密钥序列来替换被撤销的密钥。自我恢复的CA承诺针对可以读取所有数字状态的最强大的攻击者提供强大的安全保证,这将产生重大的社会影响:企业和个人将能够信任这样的CA,并将重新获得对公钥基础设施的整体信任。自行恢复的CA消除了对我们经济和社会的严重安全威胁。
英文摘要
Recent years have shown the fallacy of Certificate Authorities (CAs); insiders are able to steal master signing keys and impersonate certificates, exploitation of system vulnerabilities and other means of infiltration allow attackers to gain access to CAs and copy their keys, etc. At stake is the mere survival of public key infrastructures as trust in them is bootstrapped from trust in certificates that bind public keys to known identities. The current attack surface exposed by CAs makes trust in their issued certificates questionable. The main problem is the information that a current stolen key leaks about to-be-used future keys for signing future certificates. This project introduces a new notion of backward security allowing a CA to revoke newly reconstructed secret keys, which were maliciously modified by an attacker and are known to the attacker, before the attacker is even able to sign valid certificates. The project also provides efficient self-recovery meaning that, in the presence of a powerful adversary, CAs are able to replace revoked keys by a new non-compromised signing key sequence. Self-recovering CAs promise strong security guarantees against the most powerful attacker who can read all digital state and this will have a major societal impact: enterprises and individuals will be able to trust such CAs and will regain trust in public key infrastructures as a whole. Self-recovering CAs eliminate a serious security threat to our economy and society.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Phase I IUCRC University of Connecticut: Center for Hardware and Embedded Systems Security and Trust
  • 批准号:
    1916756
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $75.0万
  • 财政年份:
    2019
  • 负责人:
    John Chandy
  • 依托单位:
Planning IUCRC University of Connecticut: Center for Hardware and Embedded Systems Security and Trust (CHEST)
  • 批准号:
    1747754
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2018
  • 负责人:
    John Chandy
  • 依托单位:
REU Site: Trustable Computing Systems Security Research
  • 批准号:
    1359329
  • 项目类别:
    Standard Grant
  • 资助金额:
    $35.94万
  • 财政年份:
    2014
  • 负责人:
    John Chandy
  • 依托单位:
EDU: A Virtual Lab for a Hardware Security Curriculum
  • 批准号:
    1318964
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.56万
  • 财政年份:
    2013
  • 负责人:
    John Chandy
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: