首页> 外文会议>Annual international cryptology conference >The Multi-user Security of Authenticated Encryption: AES-GCM in TLS 1.3
【24h】

The Multi-user Security of Authenticated Encryption: AES-GCM in TLS 1.3

机译:身份验证加密的多用户安全性:TLS 1.3中的AES-GCM

获取原文

摘要

We initiate the study of multi-user (mu) security of authenticated encryption (AE) schemes as a way to rigorously formulate, and answer, questions about the "randomized nonce" mechanism proposed for the use of the AE scheme GCM in TLS 1.3. We (1) Give definitions of mu ind (indistinguishability) and mu kr (key recovery) security for AE (2) Characterize the intent of nonce randomization as being improved mu security as a defense against mass surveillance (3) Cast the method as a (new) AE scheme RGCM (4) Analyze and compare the mu security of both GCM and RGCM in the model where the underlying block cipher is ideal, showing that the mu security of the latter is indeed superior in many practical contexts to that of the former, and (5) Propose an alternative AE scheme XGCM having the same efficiency as RGCM but better mu security and a more simple and modular design.
机译:我们启动对认证加密(AE)方案的多用户(mu)安全性的研究,以此作为严格制定和回答有关在TLS 1.3中使用AE方案GCM提出的“随机随机数”机制问题的方法。我们(1)给出AE的mu ind(不可区分性)和mu kr(密钥恢复)安全性的定义(2)将随机数随机化的意图表征为可改善mu安全性以防御大规模监视(3)将方法转换为(新)AE方案RGCM(4)在理想的基础分组密码模型中,分析并比较GCM和RGCM的mu安全性,这表明在许多实际情况下,后者的mu安全性实际上优于(5)提出一种替代的AE方案XGCM,其效率与RGCM相同,但具有更好的mu安全性和更简单且模块化的设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号