首页> 外文会议>IEEE European Symposium on Security and Privacy >A Mechanised Cryptographic Proof of the WireGuard Virtual Private Network Protocol
【24h】

A Mechanised Cryptographic Proof of the WireGuard Virtual Private Network Protocol

机译:Wioguard虚拟专用网络协议的机械化密码证明

获取原文

摘要

WireGuard is a free and open source Virtual Private Network (VPN) that aims to replace IPsec and OpenVPN. It is based on a new cryptographic protocol derived from the Noise Protocol Framework. This paper presents the first mechanised cryptographic proof of the protocol underlying WireGuard, using the CryptoVerif proof assistant. We analyse the entire WireGuard protocol as it is, including transport data messages, in an ACCE-style model. We contribute proofs for correctness, message secrecy, forward secrecy, mutual authentication, session uniqueness, and resistance against key compromise impersonation, identity mis-binding, and replay attacks. We also discuss the strength of the identity hiding provided by WireGuard. Our work also provides novel theoretical contributions that are reusable beyond WireGuard. First, we extend CryptoVerif to account for the absence of public key validation in popular Diffie-Hellman groups like Curve25519, which is used in many modern protocols including WireGuard. To our knowledge, this is the first mechanised cryptographic proof for any protocol employing such a precise model. Second, we prove several indifferentiability lemmas that are useful to simplify the proofs for sequences of key derivations.
机译:WireGuard是一个自由和开放源码的虚拟专用网(VPN),旨在取代IPSec和OpenVPN的。它是基于从噪声协议框架衍生的新的加密协议。本文介绍了协议底层WireGuard,使用CryptoVerif证明助理的第一机械化加密证明。我们分析整个WireGuard协议,因为它是,包括交通数据信息,以ACCE风格的典范。我们的贡献证明的正确性,信息保密性,前向安全,相互认证,会议的独特性,以及抵抗密钥泄露模仿,身份MIS结合,和重放攻击。我们还讨论通过WireGuard提供的身份隐藏的实力。我们的工作还提供了可重复使用超出WireGuard新的理论贡献。首先,我们扩展CryptoVerif以考虑流行的Diffie-Hellman组像Curve25519,这是在许多现代协议,包括WireGuard使用没有公钥验证。据我们所知,这是采用这样的精确模型的任何协议第一机械化加密证明。其次,我们证明了几个indifferentiability引理是简化证明为导出密钥序列有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号