【24h】

A Provable-Security Treatment of the Key-Wrap Problem

机译:密钥包装问题的可证明安全性处理

获取原文
获取原文并翻译 | 示例

摘要

We give a provable-security treatment for the key-wrap problem, providing definitions, constructions, and proofs. We suggest that key-wrap's goal is security in the sense of deterministic authenticated-encryption (DAE), a notion that we put forward. We also provide an alternative notion, a pseudorandom injection (PRI), which we prove to be equivalent. We provide a DAE construction, SIV, analyze its concrete security, develop a blockcipher-based instantiation of it, and suggest that the method makes a desirable alternative to the schemes of the X9.102 draft standard. The construction incorporates a method to turn a PRF that operates on a string into an equally efficient PRF that operates on a vector of strings, a problem of independent interest. Finally, we consider IV-based authenticated-encryption (AE) schemes that are maximally forgiving of repeated IVs, a goal we formalize as misuse-resistant AE. We show that a DAE scheme with a vector-valued header, such as SIV, directly realizes this goal.
机译:对于密钥包装问题,我们提供了可证明的安全性处理方法,并提供了定义,构造和证明。我们建议在确定性认证加密(DAE)的意义上,密钥包装的目标是安全性,这是我们提出的概念。我们还提供了另一种概念,即伪随机注入(PRI),我们证明它是等效的。我们提供了DAE结构SIV,分析了它的具体安全性,开发了基于块密码的实例化,并建议该方法可作为X9.102标准草案的理想替代方案。该构造结合了一种方法,该方法可以将对字符串进行操作的PRF转换为对字符串矢量进行操作的等效PRF,这是一个独立的问题。最后,我们考虑基于IV的认证加密(AE)方案,该方案最大程度地避免了重复的IV,我们将这一目标正式化为可防止误用的AE。我们展示了带有向量值标头的DAE方案(例如SIV)直接实现了这一目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号