首页> 外文会议>International coference on provable security >On Modeling Terrorist Frauds Addressing Collusion in Distance Bounding Protocols
【24h】

On Modeling Terrorist Frauds Addressing Collusion in Distance Bounding Protocols

机译:关于定界协议中针对共谋的恐怖分子欺诈行为的建模

获取原文

摘要

Quite recently, distance-bounding protocols received a lot of attention as they offer a good solution to thwart relay attacks. Their security models at still unstable, especially when considering terrorist fraud. This considers the case where a malicious prover would try to bypass the protocol by colluding with an adversary without leaking his credentials. Two formal models appeared recently: one due to Fischlin and Onete and another one by Boureanu, Mitrokotsa, and Vaudenay. Both were proposed with a provably secure distance-bounding protocols (FO and SKI, respectively) providing security against all state-of-the-art threat models. So far, these two protocols are the only such ones. In this paper we compare both notions and protocols. We identify some errors in the Fischlin-Onete results. We also show that the design of the FO protocol lowers security against mafia frauds while the SKI protocol makes non-standard PRF assumptions and has lower security due to not using post-authentication. None of these protocols provide reasonable parameters to be used in practice with a good security. The next open challenge consists in providing a protocol combining both approaches and good practical parameters. Finally, we provide a new security definition against terrorist frauds which naturally inspires from the soundness notion for proof-of-knowledge protocols.
机译:最近,距离限制协议受到了广泛的关注,因为它们为阻止中继攻击提供了很好的解决方案。他们的安全模型仍然不稳定,尤其是在考虑恐怖分子欺诈行为时。这考虑了恶意证明者试图通过与对手串通而绕过协议而不会泄漏其凭据的情况。最近出现了两种正式模型:一种是由Fischlin和Onete提出的,另一种是由Boureanu,Mitrokotsa和Vaudenay提出的。两者都建议使用可证明的安全的距离限制协议(分别为FO和SKI),以提供针对所有最新威胁模型的安全性。到目前为止,这两个协议是唯一的此类协议。在本文中,我们将概念和协议进行了比较。我们在Fischlin-Onete结果中发现了一些错误。我们还显示,FO协议的设计降低了针对黑手党欺诈的安全性,而SKI协议则进行了非标准的PRF假设,并且由于未使用身份验证而具有较低的安全性。这些协议均未提供合理的参数以在实践中以良好的安全性使用。下一个开放的挑战是提供一种结合了方法和良好实用参数的协议。最后,我们提供了一个针对恐怖分子欺诈的新安全定义,自然而然地从知识证明协议的健全性概念中得到启发。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号