首页> 外文会议>IEEE European Symposium on Security and Privacy >A Mechanised Cryptographic Proof of the WireGuard Virtual Private Network Protocol
【24h】

A Mechanised Cryptographic Proof of the WireGuard Virtual Private Network Protocol

机译:WireGuard虚拟专用网协议的机械化密码证明

获取原文

摘要

WireGuard is a free and open source Virtual Private Network (VPN) that aims to replace IPsec and OpenVPN. It is based on a new cryptographic protocol derived from the Noise Protocol Framework. This paper presents the first mechanised cryptographic proof of the protocol underlying WireGuard, using the CryptoVerif proof assistant. We analyse the entire WireGuard protocol as it is, including transport data messages, in an ACCE-style model. We contribute proofs for correctness, message secrecy, forward secrecy, mutual authentication, session uniqueness, and resistance against key compromise impersonation, identity mis-binding, and replay attacks. We also discuss the strength of the identity hiding provided by WireGuard. Our work also provides novel theoretical contributions that are reusable beyond WireGuard. First, we extend CryptoVerif to account for the absence of public key validation in popular Diffie-Hellman groups like Curve25519, which is used in many modern protocols including WireGuard. To our knowledge, this is the first mechanised cryptographic proof for any protocol employing such a precise model. Second, we prove several indifferentiability lemmas that are useful to simplify the proofs for sequences of key derivations.
机译:Wioguard是一个免费的和开源虚拟专用网络(VPN),旨在替换IPSec和OpenVPN。它基于从噪声协议框架派生的新加密协议。本文介绍了Cryptoverif校正助手的底层Wioguard的第一个机械化加密证明。我们在ACCE式模型中分析整个WIROGUARD协议,包括传输数据消息,包括传输数据。我们为正确性,消息保密,前瞻保密,相互认证,会话唯一性以及对关键危害的抵抗,身份错误绑定和重放攻击的依据贡献证明,留言保密,前瞻性,互动和阻力。我们还讨论了Wioguard提供的身份隐藏的强度。我们的工作还提供了在布线之外可重复使用的新颖理论贡献。首先,我们扩展CryptoverIf以考虑在曲线25519等流行的Diffie-Hellman组中缺乏公开键验证,其在许多现代协议中使用,包括Wieguard。为了我们的知识,这是一个采用这种精确模型的任何协议的第一机械化加密证明。其次,我们证明了几种有用的次要性lemmas,可用于简化关键推导序列的证据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号