首页> 外文会议>International coference on provable security >Practical and Robust Secure Logging from Fault-Tolerant Sequential Aggregate Signatures
【24h】

Practical and Robust Secure Logging from Fault-Tolerant Sequential Aggregate Signatures

机译:从容错顺序聚合签名进行实用且鲁棒的安全日志记录

获取原文

摘要

Keeping correct and informative log files is crucial for system maintenance, security and forensics. Cryptographic logging schemes offer integrity checks that protect a log file even in the case where an attacker has broken into the system. A relatively recent feature of these schemes is resistance against truncations, i.e. the deletion and/or replacement of the end of the log file. This is especially relevant as system intruders are typically interested in manipulating the later log entries that point towards their attack. However, there are not many schemes that are resistant against truncating the log file. Those that are have at least one of the following disadvantages: They are memory intensive (they store at least one signature per log entry), or fragile (i.e. a single error in the log renders the signature invalid and useless in determining where the error occurred). We obtain a publicly-verifiable secure logging scheme that is simultaneously robust, space-efficient and truncation secure with provable security under simple assumptions. Our generic construction uses forward-secure signatures, in a plain and a sequential aggregate variant, where the latter is additionally fault-tolerant, as recently formalized by Hartung et al. [9]. Fault-tolerant schemes can cope with a number of manipulated log entries (bounded a priori) and offer strong robustness guarantees while still retaining space efficiency. Our implementation and the accompanying performance measurements confirm the practicality of our scheme.
机译:保持正确且信息丰富的日志文件对于系统维护,安全性和取证至关重要。加密日志记录方案提供完整性检查,即使在攻击者闯入系统的情况下,也可以保护日志文件。这些方案的相对较新的特征是可以抵抗截断,即删除和/或替换日志文件末尾。这一点特别相关,因为系统入侵者通常对操纵指向其攻击的以后的日志条目感兴趣。但是,没有很多方案可以抵抗截断日志文件。那些具有至少下列缺点之一:它们是内存密集型的(它们在每个日志条目中存储至少一个签名),或者是脆弱的(即,日志中的单个错误使签名无效,并且在确定错误发生的位置无用) )。我们获得了一个可公开验证的安全日志记录方案,该方案在简单的假设下同时具有鲁棒性,节省空间和截断安全性以及可证明的安全性。我们的通用结构使用前向安全签名,该签名采用了普通的和顺序的聚合变体,后者又具有容错性,正如Hartung等人最近所规范化的那样。 [9]。容错方案可以处理许多操纵的日志条目(先验有界),并提供强大的鲁棒性保证,同时仍保持空间效率。我们的实施以及随附的性能测量结果证实了该方案的实用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号