首页> 外文会议>ACM Conference on Computer and Communications Security >Revoke and Let Live: A Secure Key Revocation API for Cryptographic Devices
【24h】

Revoke and Let Live: A Secure Key Revocation API for Cryptographic Devices

机译:撤消并让Let Live:用于加密设备的安全密钥撤销API

获取原文

摘要

While extensive research addresses the problem of establishing session keys through cryptographic protocols, relatively little work has appeared addressing the problem of revocation and update of long term keys. We present an API for symmetric key management on embedded devices that supports key establishment and revocation, and prove security properties of our design in the symbolic model of cryptography. Our API supports two modes of revocation: a passive mode where keys have an expiration time, and an active mode where revocation messages are sent to devices. For the first we show that once enough time has elapsed after the compromise of a key, the system returns to a secure state, i.e. the API is robust against attempts by the attacker to use a compromised key to compromise other keys or to keep the compromised key alive past its validity time. For the second we show that once revocation messages have been received the system immediately returns to a secure state. Notable features of our designs are that all secret values on the device are revocable, and the device returns to a functionally equivalent state after revocation is complete.
机译:虽然广泛的研究解决了通过加密协议建立会话密钥的问题,但出现了对撤销和更新的长期键的问题相对较少。我们为嵌入式设备提供了一个用于对称密钥管理的API,支持关键建立和撤销,并在密码识别模型中证明我们设计的安全性。我们的API支持两种撤销模式:键具有到期时间的被动模式,以及发送到设备的撤销消息的活动模式。首先,我们显示在钥匙的妥协后经过了一次足够的时间,系统返回到安全状态,即API对攻击者尝试的稳健性,以使用受损键危及其他键或保持泄露的键钥匙曾经过它的有效时间。对于第二个,我们表明,一旦收到撤销消息,系统立即返回到安全状态。我们设计的显着特征是设备上的所有秘密值都是可撤销的,并且在撤销完成后,设备返回到功能等同状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号