【24h】

Universally Composable Notions of Key Exchange and Secure Channels

机译:密钥交换和安全通道的通用组合概念

获取原文
获取原文并翻译 | 示例

摘要

Recently, Canetti and Krawczyk (Eurocrypt'2001) formulated a notion of security for key-exchange (KE) protocols, called SK-security, and showed that this notion suffices for constructing secure channels. However, their model and proofs do not suffice for proving more general composability properties of SK-secure KE protocols. We show that while the notion of SK-security is strictly weaker than a fully-idealized notion of key exchange security, it is sufficiently robust for providing secure composition with arbitrary protocols. In particular, SK-security guarantees the security of the key for any application that desires to set-up secret keys between pairs of parties. We also provide new definitions of secure-channels protocols with similarly strong composability properties, and show that SK-security suffices for obtaining these definitions. To obtain these results we use the recently proposed framework of "universally composable (UC) security." We also use a new tool, called "non-information oracles," which will probably find applications beyond the present case. These tools allow us to bridge between seemingly limited indistinguishability-based definitions such as SK-security and more powerful, simulation-based definitions, such as UC security, where general composition theorems can be proven. Furthermore, based on such composition theorems we reduce the analysis of a full-fledged multi-session key-exchange protocol to the (simpler) analysis of individual, stand-alone, key-exchange sessions.
机译:最近,Canetti和Krawczyk(Eurocrypt'2001)提出了密钥交换(KE)协议的安全性概念,称为SK-security,表明该概念足以构建安全通道。但是,他们的模型和证明不足以证明SK安全的KE协议具有更一般的可组合性。我们显示出,尽管SK安全性的概念比完全理想化的密钥交换安全性概念弱得多,但它足以为任意协议的安全组合提供足够的鲁棒性。特别是,SK-security为希望在双方之间建立秘密密钥的任何应用程序保证了密钥的安全性。我们还提供了具有类似强大可组合性的安全通道协议的新定义,并表明SK安全性足以获取这些定义。为了获得这些结果,我们使用了最近提出的“通用可组合(UC)安全性”框架。我们还使用了一个称为“非信息预言”的新工具,该工具可能会找到当前情况以外的应用程序。这些工具使我们能够在看似有限的基于不可区分性的定义(例如SK安全性)和更强大的基于仿真的定义(例如UC安全性)之间建立桥梁,在其中可以证明一般的组成定理。此外,基于这种组合定理,我们将完整的多会话密钥交换协议的分析简化为对单个,独立的密钥交换会话的(更简单)分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号