【24h】

Protecting Against Key Escrow and Key Exposure in Identity-Based Cryptosystem

机译:在基于身份的密码系统中防止密钥托管和密钥暴露

获取原文
获取原文并翻译 | 示例

摘要

Standard identity-based cryptosystems typically rely on the assumption that secret keys are kept perfectly secure. However, in practice, there are two threats to the key security in identity-based cryptosystems. One inherent problem is key escrow, that is, the Key Generation Center (KGC) always knows a user's secret key and the malicious KGC can impersonate the user. Meanwhile, another threat is that a user's secret key may be exposed to an adversary in an insecure device, and key exposure typically means that security is entirely lost. At present, there is no solution that can simultaneously solve both of above problems. In this paper, we first present a secure key issuing and updating model for identity-based cryptosystems. Our suggestion is an intermediate between the identity-based key insulation and distributing authorities approach, and can simultaneously solve both key escrow and key exposure problems. We formalize the definition and security notion of the corresponding encryption scheme (IBKUE) and signature scheme (IBKUS), and then propose an IBKUE scheme based on Boneh-Franklin's scheme [2] and an IBKUS scheme based on Cha-Cheon's scheme [9]. Both of the schemes are secure in the remaining time periods against an adversary who compromises the KGC and obtains a user's secret key for the time periods of its choice. All the schemes in this paper are provably secure in the random oracle model.
机译:基于标准身份的密码系统通常依赖于以下假设:秘密密钥被完全保持安全。但是,实际上,基于身份的密码系统中的密钥安全存在两种威胁。一个固有的问题是密钥托管,即密钥生成中心(KGC)始终知道用户的秘密密钥,而恶意的KGC可以冒充用户。同时,另一个威胁是用户的秘密密钥可能在不安全的设备中暴露给对手,并且密钥暴露通常意味着安全性完全丧失。当前,没有可以同时解决上述两个问题的解决方案。在本文中,我们首先提出了一种用于基于身份的密码系统的安全密钥发布和更新模型。我们的建议是介于基于身份的密钥隔离和分发机构方法之间的中介,并且可以同时解决密钥托管和密钥暴露问题。我们将相应的加密方案(IBKUE)和签名方案(IBKUS)的定义和安全概念形式化,然后提出基于Boneh-Franklin方案[2]的IBKUE方案和基于Cha-Cheon方案[9]的IBKUS方案。 。两种方案在其余时间段都是安全的,可抵抗攻击者破坏KGC并在其选择的时间段内获取用户的密钥。本文中的所有方案在随机预言模型中都是可证明的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号