课题基金 / 基金详情

Cryptographic Mechanisms for Internet Security

Cryptographic Mechanisms for Internet Security
互联网安全的加密机制
批准号:
0129617
负责人:
Mihir Bellare
金额:
$21.86万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-03-01 至 2006-02-28

项目摘要

项目成果

Mihir Bellare的其他基金

相似基金

相关文献

中文摘要
翻译
互联网打开了新可能性的大门,但也带来了新的风险。互联网安全是一个公认的跨越数学、系统和社会学之间的边界的问题,而灵丹妙药是不太可能的。该提案的目标是隔离并针对安全问题中的几个组件,这些组件在实践中对互联网安全具有实际影响,并且定义足够明确,可以在项目的时间框架和资源范围内取得明确、有记录和可识别的进展。选定的问题涉及当前和未来互联网安全协议和标准的密码学组成部分,涉及认证、访问控制、隐私、密钥分发和密钥泄露等技术领域,并涉及密码学和系统安全之间的差距。提供高质量、高成本效益的加密机制,并将它们安全地捆绑在一起,是一个挑战。加密方案很容易指定,但很难验证,而且以包含需要很长时间才能发现的漏洞而臭名昭著。该方案将采用面向实践的可证明安全方法来改进密码机制的安全保证。该方法由Bellare和Rogaway开发,在提供有理论保证的实用密码学方面已经取得了良好的记录。这种方法过去的成功包括HMAC和OAEP算法,它们已经被许多标准机构采用并被广泛实现。我们建议解决的前两个问题与协议的安全性有关,例如SSL。研究人员建议调查一种常见但未在理论上分析的机制的安全性,即对非对称加密和数字签名使用相同的密钥。研究人员将寻求确定在什么情况下这是安全的,特别是关注现有的标准。然后,研究人员将建议在会话密钥交换的可证明安全性的基础上,研究作为安全协议核心的会话密钥交换协议的安全性,如SSL、TLS或3GPP的协议。研究人员希望从某种加密机制获得的最大安全威胁可能只是密钥泄露:入侵者闯入系统并泄露底层密钥。这个问题跨越了安全和密码学之间的界限,研究人员提出的下两个问题是考虑两种密码学方法来解决它。第一个是前向安全,其目标不是防止密钥暴露,而是通过确保密钥过去的使用不会因其暴露而受到损害来减轻其造成的损害。研究人员提出了两项与前向安全有关的具体研究,一项是在签名领域,另一项是在伪随机数生成领域。第二个问题与人类可记忆的密钥或密码有关。这些漏洞的优点是不会通过破解而暴露密钥,但也有其他缺点,最明显的是会受到字典攻击。几家公司已经提出了某种形式的服务器辅助的、基于密码的身份验证。为此,研究人员调查了一些潜在机制的安全性。
英文摘要
The Internet has opened the door to new possibilities, but also brought with it new risks.Internet security is a widely recognized problem crossing the boundaries between mathematics,systems and sociology, and panaceas are unlikely. The goal of this proposal is to isolate andtarget a few components of the security problem that have real impact on Internet security inpractice and are well-defined enough that clear, documented, and identifiable progress can be madewithin the time-frame and resources of the project. The chosen problems relate to cryptographiccomponents of current and future Internet security protocols and standards, in technical areas suchas authentication, access control, privacy, key distribution and key compromise, and to bridgingthe gap between cryptography and systems security. Providing high-quality, cost-efective cryptographic mechanisms, and tying them together se-curely,is a challenge. Cryptographic schemes are easy to specify but hard to validate, and notoriousfor containing bugs that take a long time to be discovered. This proposal will employ the practice-oriented provable-security approach toimprove security guarantees of cryptographic mechansisms.Developed by Bellare and Rogaway, this approach already has a track record in delivering prac-tical cryptography backed by theoretical guarantees. Past successes of this method include theHMAC andOAEP algorithms which have been adopted by numerous standards bodies and widelyimplemented. The first two problems that we propose to address are related to the security of protocolssuch as SSL. The researchers propose to investigate the security ofa mechanism that is common practice butnot analyzed in theory, namely to use the same key for both asymmetric encryption and digitalsignatures. The researchers will seek to determine under what circumstances this is secure, with particularfocus on existing standards. The researchers will then propose to investigate the security of the session key exchange protocols at the heart of security protocols like SSL, TLS or that of 3GPP, building on pastwork in provable security for session key exchange. The greatest threat to the security the researcher may hope to obtain from some cryptographic mechanismmay simply be key exposure: an intruder breaks into the system and compromises the underlyingkey. This problem crosses the boundary between security and cryptography, and the next twoproblems proposed by the researcheris to consider two cryptographic approaches to it. The first is forward-security, whose goal is not to prevent key exposure, but to mitigate the damage it causes by making sure that past uses of a key are not compromised by its exposure. The researchers propose two specific pieces of research related to forward security, one in the domain of signatures and the other in the domainof pseudorandom number generation. The second problem relates to human-memorizable keys, orpasswords. These have the advantage of not being subject to key exposure via breakin, but haveother disadvantages, most notably being subject to dictionary attack. Several corporations haveproposed some form of server-aided, password-based authentication. The researcher looks into the security of some of the potential mechanisms to this end.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Practice-Driven Cryptographic Theory
  • 批准号:
    2154272
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Mihir Bellare
  • 依托单位:
SaTC: CORE: Small: Foundations of Applied Cryptography
  • 批准号:
    1717640
  • 项目类别:
    Standard Grant
  • 资助金额:
    $32.65万
  • 财政年份:
    2017
  • 负责人:
    Mihir Bellare
  • 依托单位:
TWC: Small: Subversion-Resistant Cryptography
  • 批准号:
    1526801
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2015
  • 负责人:
    Mihir Bellare
  • 依托单位:
TWC: Medium: Collaborative: Deconstructing Encryption
  • 批准号:
    1228890
  • 项目类别:
    Standard Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2012
  • 负责人:
    Mihir Bellare
  • 依托单位:
国内基金
海外基金
Exploring the Intrinsic Mechanisms of CEO Turnover and Market
  • 批准号:
    --
  • 项目类别:
    外国学者研究基金
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    HAOFEI Z
  • 依托单位:
Exploring the Intrinsic Mechanisms of CEO Turnover and Market Reaction: An Explanation Based on Information Asymmetry
  • 批准号:
    W2433169
  • 项目类别:
    外国学者研究基金项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    HAOFEI ZHANG
  • 依托单位: