首页> 外文会议>International Conference on Selected Areas in Cryptography >Analysis and Improvement of an Authentication Scheme in Incremental Cryptography
【24h】

Analysis and Improvement of an Authentication Scheme in Incremental Cryptography

机译:增量密码学中认证方案的分析与改进

获取原文

摘要

Introduced in cryptography by Bellare, Goldreich and Goldwasser in 1994, incrementality is an attractive feature that enables to update efficiently a cryptographic output like a ciphertext, a signature or an authentication tag after modifying the corresponding input. This property is very valuable in large scale systems where gigabytes of data are continuously processed (e.g. in cloud storage). Adding cryptographic operations on such systems can decrease dramatically their performance and incrementality is an interesting solution to have security at a reduced cost. We focus on the so-called XOR-scheme, the first incremental authentication construction proposed by Bellare, Goldreich and Goldwasser, and the only strongly incremental scheme (i.e. incremental regarding insert and delete update operations at any position in a document). Surprisingly, we found a simple attack on this construction that breaks the basic security claimed by the authors in 1994 with only one authentication query (not necessarily chosen). Our analysis gives different ways to fix the scheme; some of these patches are discussed in this paper and we provide a security proof for one of them.
机译:1994年Bellare,Goldreich和Goldwasser在加密术中引入,增量是一个有吸引力的功能,使得在修改相应输入之后,可以有效地更新加密输出,签名或身份验证标签。此属性在大规模系统中非常有价值,其中数据千兆字节被连续处理(例如,在云存储中)。在这种系统上添加加密操作可以大大降低它们的性能和增量是一个有趣的解决方案,以降低成本。我们专注于所谓的XOR方案,这是Bellare,Goldreich和Goldwasser提出的第一个增量认证构建,以及唯一强大的增量方案(即文档中的任何职位的插入和删除更新操作的增量)。令人惊讶的是,我们发现了一个简单的攻击这一结构,即1994年的作者宣称的基本安全,只有一个认证查询(不一定被选中)。我们的分析提供了解决方案的不同方式;本文讨论了一些这些补丁,我们为其中一个提供了安全证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号