首页> 外文会议>ACM conference on Computer and communications security >A model and architecture for pseudo-random generation with applications to /dev/random
【24h】

A model and architecture for pseudo-random generation with applications to /dev/random

机译:用于/开/随机的应用程序的伪随机生成的模型和架​​构

获取原文

摘要

We present a formal model and a simple architecture for robust pseudorandom generation that ensures resilience in the face of an observer with partial knowledge/control of the generator's entropy source. Our model and architecture have the following properties:Resilience. The generator's output looks random to an observer with no knowledge of the internal state. This holds even if that observer has complete control over data that is used to refresh the internal state.Forward security. Past output of the generator looks random to an observer, even if the observer learns the internal state at a later time.Backward security/Break-in recovery. Future output of the generator looks random, even to an observer with knowledge of the current state, provided that the generator is refreshed with data of sufficient entropy.Architectures such as above were suggested before. This work differs from previous attempts in that we present a formal model for robust pseudo-random generation, and provide a formal proof within this model for the security of our architecture. To our knowledge, this is the first attempt at a rigorous model for this problem.Our formal modeling advocates the separation of the entropy extraction phase from the output generation phase. We argue that the former is information-theoretic in nature, and could therefore rely on combinatorial and statistical tools rather than on cryptography. On the other hand, we show that the latter can be implemented using any standard (non-robust) cryptographic PRG.We also discuss the applicability of our architecture for applications such as /dev/(u)random in Linux and pseudorandom generation on smartcards.
机译:我们提出一个正式的模型和一个简单的架构,强大的伪随机生成,可确保与发电机的熵源的部分知识/控制观察者的脸恢复能力。我们的模型和体系结构具有以下属性:弹性。发电机的输出看起来随意,没有内部状态的知识的观察员。这适用即使观察者具有超过其用于刷新的内部状态数据的完全控制。转发安全。所述发电机的输出过去看起来随机给观察者,即使观察者获悉在稍后的时间的内部状态。后向安全/磨合恢复。发电机的未来输出看起来是随机的,甚至到与当前状态的知识的观察者,条件是所述生成器被刷新以足够entropy.Architectures诸如上述的数据之前,建议。这项工作不同之处在于,我们提出了稳健的伪随机生成一个正式的模型,并提供该模型为我们架构的安全范围内的正式证明以前的尝试。据我们所知,这是在该问题。我们正式建模严格模型的第一次尝试主张熵提取相位的从输出生成相的分离。我们认为,前者是信息理论的性质,因此可以依靠组合和统计工具,而不是密码。在另一方面,我们表明,后者可以使用任何标准来实现(非稳健的)密码PRG.We还讨论了我们的架构的适用性等应用为/ dev /(U)在Linux中随机和伪随机在智能卡上一代。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号