...
首页> 外文期刊>International Journal of Information Security >Anonymous attestation with user-controlled linkability
【24h】

Anonymous attestation with user-controlled linkability

机译:具有用户控制的链接能力的匿名证明

获取原文
获取原文并翻译 | 示例

摘要

This paper is motivated by the observation that existing security models for direct anonymous attestation (DAA) have problems to the extent that insecure protocols may be deemed secure when analysed under these models. This is particularly disturbing as DAA is one of the few complex cryptographic protocols resulting from recent theoretical advances actually deployed in real life. Moreover, standardization bodies are currently looking into designing the next generation of such protocols. Our first contribution is to identify issues in existing models for DAA and explain how these errors allow for proving security of insecure protocols. These issues are exhibited in all deployed and proposed DAA protocols (although they can often be easily fixed). Our second contribution is a new security model for a class of "pre-DAA scheme", that is, DAA schemes where the computation on the user side takes place entirely on the trusted platform. Our model captures more accurately than any previous model the security properties demanded from DAA by the trusted computing group (TCG), the group that maintains the DAA standard. Extending the model from pre-DAA to full DAA is only a matter of refining the trust models on the parties involved. Finally, we present a generic construction of a DAA protocol from new building blocks tailored for anonymous attestation. Some of them are new variations on established ideas and may be of independent interest. We give instantiations for these building blocks that yield a DAA scheme more efficient than the one currently deployed, and as efficient as the one about to be standardized by the TCG which has no valid security proof.
机译:本文的动机是观察到,现有的直接匿名证明(DAA)安全模型存在一定程度的问题,即在这些模型下进行分析时,不安全的协议可能被认为是安全的。这尤其令人不安,因为DAA是由于实际部署在现实中的最新理论进展而导致的为数不多的复杂密码协议之一。而且,标准化机构目前正在研究设计这种协议的下一代。我们的第一个贡献是识别DAA现有模型中的问题,并解释这些错误如何证明不安全协议的安全性。这些问题在所有已部署和建议的DAA协议中都有体现(尽管通常可以轻松解决)。我们的第二个贡献是针对一类“ DAA之前方案”(即DAA方案)的新安全模型,在该模型中,用户端的计算完全在可信平台上进行。我们的模型比任何以前的模型都能更准确地捕获可信计算组(TCG)对DAA所要求的安全属性,TCG是维护DAA标准的组。将模型从DAA之前扩展到完整的DAA只是在所涉各方上完善信任模型的问题。最后,我们从为匿名证明量身定制的新构建块中介绍了DAA协议的一般构造。其中一些是既定观念的新变体,可能具有独立利益。我们为这些构建模块提供了实例化,这些实例产生的DAA方案比当前部署的DAA方案更有效,并且效率与即将由没有有效安全证明的TCG标准化的DAA方案相同。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号