首页> 外文会议>2012 IEEE 25th computer security foundations symposium >Verifying Privacy-Type Properties in a Modular Way
【24h】

Verifying Privacy-Type Properties in a Modular Way

机译:以模块化方式验证隐私类型属性

获取原文
获取原文并翻译 | 示例

摘要

Formal methods have proved their usefulness for analysing the security of protocols. In this setting, privacy-type security properties (e.g. vote-privacy, anonymity, unlink ability) that play an important role in many modern applications are formalised using a notion of equivalence. In this paper, we study the notion of trace equivalence and we show how to establish such an equivalence relation in a modular way. It is well-known that composition works well when the processes do not share secrets. However, there is no result allowing us to compose processes that rely on some shared secrets such as long term keys. We show that composition works even when the processes share secrets provided that they satisfy some reasonable conditions. Our composition result allows us to prove various equivalence-based properties in a modular way, and works in a quite general setting. In particular, we consider arbitrary cryptographic primitives and processes that use non-trivial else branches. As an example, we consider the ICAO e-passport standard, and we show how the privacy guarantees of the whole application can be derived from the privacy guarantees of its sub-protocols.
机译:形式化方法已经证明了其对分析协议安全性的有用性。在这种情况下,使用等效概念将在许多现代应用中起重要作用的隐私类型的安全属性(例如投票隐私,匿名性,取消链接能力)正式化。在本文中,我们研究了痕量对等的概念,并展示了如何以模块化方式建立这种对等关系。众所周知,当过程不共享秘密时,组合可以很好地工作。但是,没有结果允许我们编写依赖于某些共享机密(例如长期密钥)的过程。我们证明即使流程共享一些秘密条件(只要它们满足一些合理的条件),组合就可以工作。我们的合成结果使我们能够以模块化的方式证明各种基于等价的特性,并且可以在相当普遍的环境下工作。特别是,我们考虑使用非平凡else分支的任意加密原语和过程。例如,我们考虑了ICAO电子护照标准,并说明了如何从子协议的隐私保证中得出整个应用程序的隐私保证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号