Strongly Anonymous Ratcheted Key Exchange

Strongly Anonymous Ratcheted Key Exchange
复制标题

DOI:
10.1007/978-3-031-22969-5_5
复制
发表时间:
2022
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Benjamin Dowling;Eduard Hauck;Doreen Riepel;Paul Rösler
Benjamin Dowling;Eduard Hauck;Doreen Riepel;Paul Rösler
中科院分区:
其他
文献类型:
--
作者:
Benjamin Dowling;Eduard Hauck;Doreen Riepel;Paul Rösler

文献摘要

被引文献

相似文献

安全性是一个(抽象的)安全目标,对受威胁的用户组尤为重要。因此,广泛部署的通信协议实施各种措施来隐藏不同类型的信息(即,元数据)。在实际定义匿名性之前,我们考虑一个目标用户组可能会感到担忧的攻击向量:持续,临时暴露他们的秘密。这种攻击媒介的例子包括故意在受害者的设备上植入病毒,以及当他们的用户被拘留时的物理访问。受Signal的双棘轮算法的启发,棘轮(或连续)密钥交换(RKE)是一类新颖的协议,它增加了对用户秘密临时暴露的可信性和真实性保证。为此,RKE定期更新用户秘密,以使过去和未来暴露造成的损害最小化;这分别称为后妥协安全性和前向安全性。通过这项工作,我们是第一个利用RKE的优势,在用户秘密临时暴露的情况下实现强大的匿名性保证。我们扩展了现有的RKE定义,以捕获网络上看到的密文与从用户设备暴露的秘密之间的相互关联的攻击。虽然乍一看,强真实性(和保密性)与强匿名性相冲突,但我们的匿名性定义在不削弱其他目标的情况下尽可能强。我们构建了强匿名性,真实性和保密性保护的RKE,并且沿着这条路,开发了适用于我们特定用例之外的新工具:可更新和可随机化签名以及可更新和可随机化公钥加密。对于这两个新的原语,我们建立有效的结构。
Anonymity is an (abstract) security goal that is especially important to threatened user groups. Therefore, widely deployed communication protocols implement various measures to hide different types of information (i.e., metadata) about their users. Before actually defining anonymity, we consider an attack vector about which targeted user groups can feel concerned: continuous, temporary exposure of their secrets. Examples for this attack vector include intentionally planted viruses on victims’ devices, as well as physical access when their users are detained.Inspired bySignal’s Double-Ratchet Algorithm,Ratcheted(orContinuous)Key Exchange(RKE) is a novel class of protocols that increaseconfidentialityandauthenticityguarantees against temporary exposure of user secrets. For this, an RKE regularly renews user secrets such that the damage due to past and future exposures is minimized; this is calledPost-Compromise SecurityandForward-Secrecy, respectively.With this work, we are the first to leverage the strength of RKE for achieving stronganonymityguarantees under temporary exposure of user secrets. We extend existing definitions for RKE to capture attacks that interrelate ciphertexts, seen on the network, with secrets, exposed from users’ devices. Although, at first glance, strong authenticity (and confidentiality) conflicts with strong anonymity, our anonymity definition is as strong as possible without diminishing other goals.We build strongly anonymity-, authenticity-, and confidentiality-preserving RKE and, along the way, develop new tools with applicability beyond our specific use-case:Updatable and Randomizable Signaturesas well asUpdatable and Randomizable Public Key Encryption. For both new primitives, we build efficient constructions.