首页> 外文会议>Paradigms in cryptology-mycrypt 2016: malicious and exploratory cryptology >Controlled Randomness - A Defense Against Backdoors in Cryptographic Devices
【24h】

Controlled Randomness - A Defense Against Backdoors in Cryptographic Devices

机译:受控随机性-防范密码设备中的后门

获取原文
获取原文并翻译 | 示例

摘要

Security of many cryptographic protocols is conditioned by quality of the random elements generated in the course of the protocol execution. On the other hand, cryptographic devices implementing these protocols are designed given technical limitations, usability requirements and cost constraints. This frequently results in black box solutions. Unfortunately, the black box random number generators enable creating backdoors. So effectively the signing keys may be stolen, authentication protocol can be broken enabling impersonation, confidentiality of encrypted communication is not guaranteed anymore. In this paper we deal with this problem. The solution proposed is a generation of random parameters such that: (a) the protocols are backwards compatible (a protocol participant gets additional data that can be ignored), (b) verification of randomness might be executed any time without any notice, so a device is forced to behave honestly, (c) the solution makes almost no change in the existing protocols and therefore is easy to implement, (d) the owner of a cryptographic device becomes secured against its designer and manufacturer that otherwise might be able to predict the output of the generator and break the protocol. We give a few application examples of this technique for standard schemes.
机译:许多密码协议的安全性取决于协议执行过程中生成的随机元素的质量。另一方面,在给定技术限制,可用性要求和成本约束的情况下,设计实现这些协议的密码设备。这经常导致黑匣子解决方案。不幸的是,黑匣子随机数生成器允许创建后门。因此,有效的签名密钥可能被盗,身份验证协议可能被破坏,从而可以进行模拟,并且不再保证加密通信的机密性。在本文中,我们处理这个问题。提出的解决方案是生成随机参数,以便:(a)协议向后兼容(协议参与者获得可以忽略的附加数据),(b)可以随时执行随机性验证而无需任何通知,因此设备被迫诚实行事;(c)该解决方案几乎不对现有协议进行任何更改,因此易于实施;(d)加密设备的所有者受到其设计者和制造商的保护,否则他们可能能够预测生成器的输出并破坏协议。我们为标准方案提供了此技术的一些应用示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号