Foundations and Real-World Aspects of Secure Cryptographic Connections
Foundations and Real-World Aspects of Secure Cryptographic Connections
批准号:
406593006
负责人:
Dr. Felix Günther
金额:
$0.0万
依托单位:
依托单位国家:
德国
项目类别:
Research Fellowships
财政年份:
2018
资助国家:
德国
项目状态:
已结题
起止时间:
2017-12-31 至 2019-12-31
中文摘要
安全连接是当今互联网基础设施的核心,保护传输中数据的机密性、完整性和真实性,例如,在进行网上银行、访问电子邮件或与朋友聊天时。底层加密协议(例如,著名的传输层安全(TLS)协议)由两个核心组件组成:密钥交换协议首先在可能不安全的网络上的两个通信伙伴之间建立共享密钥。然后在后续的安全通道协议中使用该密钥来保护要通信的实际数据。密钥交换和安全通道的研究是密码学的一个基础研究课题,有大量的工作支撑这类协议的经典设计。然而,在实践中,安全连接协议的新设计超越了密码学理论在技术和安全目标方面所能包含的当前理解状态。主要的例子是即将推出的TLS 1.3版本,目前由互联网工程任务组(Internet Engineering Task Force)开发,或者新颖的安全消息传递协议Signal(也是底层协议,例如WhatsApp、Facebook Messenger或谷歌Allo),这些协议每天都被数百万到数十亿的用户和设备使用。由于这些协议支撑着我们日常交互的安全性,因此理解这些新设计的安全性并根据科学坚实的理论基础检查它们的优缺点是至关重要的。拟议的项目将在扩展加密安全模型方面提供坚实的基础,并根据新建立的理解评估拟议和部署的真实世界协议的实际安全性。为此,我们将设计新颖的形式,捕捉最近协议设计中提出的高级方面。一个主要的焦点将是一个重要和强大的安全保障,防止秘密的妥协(所谓的“向前保密”)。我们将研究如何在安全通道中实现前向保密,以及在建立低延迟的通信密钥时如何实现前向保密。安全连接的新设计还涉及到应用程序如何使用这些连接,以及它们对所使用的组件要求哪些属性。因此,我们将研究最近的连接协议设计如何与应用程序以及设计所依赖的底层加密构建块集成。这使我们能够解释新设计对应用程序提供的安全性以及对其组件引入的需求的影响。通过这些步骤,提出的项目将提高在实践中部署的新型安全连接协议的密码学理解及其理论基础。
英文摘要
Secure connections are at the heart of today's Internet infrastructure, protecting confidentiality, integrity, and authenticity of data in transit, e.g., when doing online banking, accessing emails, or chatting with friends. The underlying cryptographic protocols (e.g., the prominent Transport Layer Security (TLS) protocol) are composed of two core components: A key exchange protocol first establishes a shared secret key between the two communication partners over a potentially insecure network. This key is then used in the follow-up secure channel protocol to protect the actual data to be communicated.The study of key exchange and secure channels is a foundational research topic in cryptography, with a substantial body of work underpinning classical designs for such protocols. Nevertheless, novel designs of secure connection protocols in practice go beyond what the current state of understanding in cryptographic theory can comprise in terms of techniques and security goals. Prime examples are the upcoming TLS version 1.3 currently developed by the Internet Engineering Task Force or the novel secure messaging protocol Signal (also underlying, e.g., WhatsApp, Facebook Messenger, or Google Allo), which are in daily use by millions to billions of users and devices. As these protocols underpin the security of our day-to-day interactions, it is however crucial to understand the security of these novel designs and to examine their strengths and weaknesses based on scientifically solid theoretical foundations.The proposed project will provide such solid foundations in terms of extended cryptographic security models, as well as assess the practical security of proposed and deployed real-world protocols based on the newly established understanding. To this end, we will devise novel formalisms capturing advanced aspects put forward in recent protocol designs. One major focus will be on an important and strong security guarantee protecting against compromises of secrets (so-called "forward secrecy"). We will study how forward secrecy can be achieved in a secure channel as well as when establishing the communication key with low latency. Novel designs of secure connections also have implications on how these connections are used by application programs and what properties they demand from the components they employ. Therefore, we will study how recent connection protocol designs integrate with application programs as well as with the underlying cryptographic building blocks the designs rely upon. This allows us to interpret the effects of novel designs both on the security they provide to applications and on the requirements they introduce to their components. Through these steps, the proposed project will improve the cryptographic understanding of novel secure connection protocols deployed in practice and their theoretical foundations.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1007/978-3-030-45724-2_1
发表时间:
2020-03
期刊:
Advances in Cryptology – EUROCRYPT 2020
影响因子:
--
作者:
[M. Bellare;Hannah Davis;Felix Günther]
通讯作者:
M. Bellare;Hannah Davis;Felix Günther
DOI:
10.1007/978-3-030-29962-0_25
发表时间:
2019-09
期刊:
影响因子:
--
作者:
[Jacqueline Brendel;M. Fischlin;Felix Günther]
通讯作者:
Jacqueline Brendel;M. Fischlin;Felix Günther
DOI:
10.1007/s00145-021-09384-1
发表时间:
2020-08
期刊:
Journal of Cryptology
影响因子:
3
作者:
[Benjamin Dowling;M. Fischlin;Felix Günther;D. Stebila]
通讯作者:
Benjamin Dowling;M. Fischlin;Felix Günther;D. Stebila
国内基金
海外基金
Immuno-Real Time PCR法精确定量血清MG7抗原及在早期胃癌预警中的价值
-
批准号:30600737
-
项目类别:青年科学基金项目
-
资助金额:22.0万元
-
批准年份:2006
-
负责人:陈峥
-
依托单位:
无色ReAl3(BO3)4(Re=Y,Lu)系列晶体紫外倍频性能与器件研究
-
批准号:60608018
-
项目类别:青年科学基金项目
-
资助金额:28.0万元
-
批准年份:2006
-
负责人:叶宁
-
依托单位: