...
首页> 外文期刊>Journal of computer security >Practical and provably secure distance-bounding
【24h】

Practical and provably secure distance-bounding

机译:实用且可证明的安全距离限制

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

From contactless payments to remote car unlocking, many applications are vulnerable to relay attacks. Distance bounding protocols are the main practical countermeasure against these attacks. In this paper, we present a formal analysis of SKI, which recently emerged as the first family of lightweight and provably secure distance bounding protocols. More precisely, we explicate a general formalism for distance-bounding protocols, which lead to this practical and provably secure class of protocols (and it could lead to others). We prove that SKI and its variants are provably secure, even under the real-life setting of noisy communications, against the main types of relay attacks: distance-fraud and generalised versions of mafia-and terrorist-fraud. To attain resistance to terrorist-fraud, we reinforce the idea of using secret sharing, combined with the new notion of a leakage scheme. In view of resistance to generalised mafia-frauds (and terrorist-frauds), we present the notion of circular-keying for pseudorandom functions (PRFs); this notion models the employment of a PRF, with possible linear reuse of the key. We also identify the need of PRF masking to fix common mistakes in existing security proofs/claims. Finally, we enhance our design to guarantee resistance to terrorist-fraud in the presence of noise.
机译:从非接触式支付到远程汽车解锁,许多应用程序容易受到中继攻击。距离限制协议是针对这些攻击的主要实际对策。在本文中,我们对SKI进行了形式化分析,SKI最近作为第一个轻量级且可证明是安全的距离限制协议系列出现。更准确地说,我们阐述了限界协议的一般形式,这导致了这种实用且可证明是安全的协议类(并且可能导致其他)。我们证明,即使在嘈杂的现实环境中,SKI及其变体也可针对中继攻击的主要类型:距离欺诈以及黑手党和恐怖分子欺诈的广义版本,证明是安全的。为了获得对恐怖分子欺诈的抵制,我们加强了使用秘密共享的思想,并结合了泄漏计划的新概念。考虑到对广义黑手党欺诈(和恐怖分子欺诈)的抵制,我们提出了伪随机函数(PRF)的循环密钥的概念。这个概念模拟了PRF的使用,并可能对密钥进行线性重用。我们还确定需要使用PRF屏蔽来解决现有安全证明/声明中的常见错误。最后,我们改进设计,以确保在存在噪音的情况下抵抗恐怖分子的欺诈行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号