Cryptanalysis and protocol failures
Cryptanalysis and protocol failures
复制标题
密码分析和协议失败
DOI:
10.1145/188280.188298
复制
发表时间:
1994
期刊:
影响因子:
--
通讯作者:
G. J. Simmons
中科院分区:
文献类型:
--
作者:
G. J. Simmons
56 November 1994/Vol. 37, No. 11 сомам шмпелтиана, он тнн Ӑем ost information integrity protocols depend crucially on one or more cryptographic or cryptolike operations to deny unauthorized access to or use of information whose integrity the protocol is intended to ensure. Obviously, if the underlying cryptoalgorithm were broken, then the intended function of the protocol could be subverted. What is not obvious, however, and indeed often comes as a shock to the protocol designer or user, is that a protocol can be completely subverted without impeaching, or even eroding, the security of the underlying cryptoalgorithm. There are examples of key distribution protocols that distrib-ute keys to unintended recipients, secrecy protocols that pub-licly reveal the contents of (supposedly) secret communica-tions, digital signature protocols that make forgery easy-all based on cryptoalgorithms that are sound so far as is known. At least one case involves Vernam encryption/decryption, which when used with a properly chosen one-time key is well known to be unconditionally secure [4]; in spite of this the protocol fails totally. A failure of this dramatic type is said to be a protocol failure. In many protocols, of course, the security of the cryptographic portion is progressively weakened as a result of the protocol being exercised–say, by reducing the size of the key space that one would have to search to identify an active cryptographic key—but these are not considered examples of true protocol failures, even though they are clearly examples of potential sources of failure in the intended security function (s) of a protocol. Finding and fixing failures of the latter type is the function of conventional analysis of cryptoalgorithms. True protocol failures, however, since they are not a consequence of weaknesses in the cryptoalgorithm, require an entirely different type of analysis—a type of cryptanalysis of the protocol itself. The purpose of this article is twofold: first to present some convincing examples of real-world protocol failures and then to use these examples to motivate a discussion of general principles for the cryptanalysis of protocols.