...
首页> 外文期刊>Journal of computer security >Per-session security: Password-based cryptography revisited
【24h】

Per-session security: Password-based cryptography revisited

机译:每次会话安全性:重新访问基于密码的加密

获取原文
获取原文并翻译 | 示例
           

摘要

Cryptographic security is usually defined as a guarantee that holds except when a bad event with negligible probability occurs, and nothing is guaranteed in that bad case. However, in settings where such failure can happen with substantial probability, one needs to provide guarantees even for the bad case. A?typical example is where a (possibly weak) password is used instead of a secure cryptographic key to protect a session, the bad event being that the adversary correctly guesses the password. In a situation with multiple such sessions, a per-session guarantee is desired: any session for which the password has not been guessed remains secure, independently of whether other sessions have been compromised. A?new formalism for stating such gracefully degrading security guarantees is introduced and applied to analyze the examples of password-based message authentication and password-based encryption. While a natural per-message guarantee is achieved for authentication, the situation of password-based encryption is more delicate: a per-session confidentiality guarantee only holds against attackers for which the distribution of password-guessing effort over the sessions is known in advance. In contrast, for more general attackers without such a restriction, a strong, composable notion of security cannot be achieved.
机译:加密安全通常被定义为保证,除了发生具有可忽略概率的错误事件,并且在该案例中没有保证。但是,在这种失败可能以大量概率发生的情况下,即使对于不良案例也需要提供保证。 a?典型的例子是使用(可能弱)密码而不是安全加密密钥来保护会话,错误的事件是对手正确猜测密码。在多个此类会话的情况下,需要每次会话保证:无论是何种会话是否受到损害,密码尚未猜到的任何会话都仍然是安全的。 a?介绍了用于说明这类优雅降级安全保障的新形式主义,并应用于分析基于密码的消息认证和基于密码的加密的示例。虽然实现了自然的每留言保证进行认证,但基于密码的加密情况更精细:每次会话机密性保证只能抵御攻击者,以便提前已知在会话上的密码猜测努力的分配。相比之下,对于没有这种限制的更普遍的攻击者,无法实现强大,可协调的安全概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号