Strongly Anonymous Ratcheted Key Exchange
Strongly Anonymous Ratcheted Key Exchange
复制标题
DOI:
10.1007/978-3-031-22969-5_5
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Benjamin Dowling;Eduard Hauck;Doreen Riepel;Paul Rösler
中科院分区:
文献类型:
--
作者:
Benjamin Dowling;Eduard Hauck;Doreen Riepel;Paul Rösler
Anonymity is an (abstract) security goal that is especially important to threatened user groups. Therefore, widely deployed communication protocols implement various measures to hide different types of information (i.e., metadata) about their users. Before actually defining anonymity, we consider an attack vector about which targeted user groups can feel concerned: continuous, temporary exposure of their secrets. Examples for this attack vector include intentionally planted viruses on victims’ devices, as well as physical access when their users are detained.Inspired bySignal’s Double-Ratchet Algorithm,Ratcheted(orContinuous)Key Exchange(RKE) is a novel class of protocols that increaseconfidentialityandauthenticityguarantees against temporary exposure of user secrets. For this, an RKE regularly renews user secrets such that the damage due to past and future exposures is minimized; this is calledPost-Compromise SecurityandForward-Secrecy, respectively.With this work, we are the first to leverage the strength of RKE for achieving stronganonymityguarantees under temporary exposure of user secrets. We extend existing definitions for RKE to capture attacks that interrelate ciphertexts, seen on the network, with secrets, exposed from users’ devices. Although, at first glance, strong authenticity (and confidentiality) conflicts with strong anonymity, our anonymity definition is as strong as possible without diminishing other goals.We build strongly anonymity-, authenticity-, and confidentiality-preserving RKE and, along the way, develop new tools with applicability beyond our specific use-case:Updatable and Randomizable Signaturesas well asUpdatable and Randomizable Public Key Encryption. For both new primitives, we build efficient constructions.