首页> 外文期刊>Information and computation >A generic security API for symmetric key management on cryptographic devices
【24h】

A generic security API for symmetric key management on cryptographic devices

机译:通用安全性API,用于加密设备上的对称密钥管理

获取原文
获取原文并翻译 | 示例

摘要

We present a new symmetric key management API for cryptographic devices intended to implement security protocols in distributed systems. Our API has a formal security policy and proofs of security in the symbolic model, under various threat scenarios. This sets it apart from previous APIs such as RSA PKCS#11, which are under-specified, lack a clear security policy and are often subject to attacks. Our design is based on the principle of explicitness: the security policy for a key must be given at creation time, and this policy is then included in any ciphertext containing the key. Our API also contains novel features such as the possibility of insisting on a freshness check before accepting an encrypted key for import. To show the applicability of our design, we give an algorithm for automatically instantiating the API commands for a given key management protocol and apply it on the Clark-Jacob protocols suite.
机译:我们为加密设备提出了一种新的对称密钥管理API,旨在在分布式系统中实现安全协议。我们的API拥有正式的安全策略,并且在各种威胁情况下都具有符号模型中的安全性证明。这使其与以前的API(例如RSA PKCS#11)相区别,后者的规格不足,缺乏明确的安全策略,并且经常受到攻击。我们的设计基于明确性原则:必须在创建时给出密钥的安全策略,然后将该策略包含在任何包含密钥的密文中。我们的API还包含一些新颖的功能,例如可以在接受导入的加密密钥之前坚持进行新鲜度检查。为了展示我们设计的适用性,我们给出了一种算法,该算法可以自动实例化给定密钥管理协议的API命令,并将其应用于Clark-Jacob协议套件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号