首页> 外文OA文献 >Revoke and Let Live: A Secure Key Revocation API for Cryptographic Devices
【2h】

Revoke and Let Live: A Secure Key Revocation API for Cryptographic Devices

机译:撤消并释放:用于加密设备的安全密钥撤回API

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

While extensive research addresses the problem of establishing session keys through cryptographic protocols, relatively little work has appeared addressing the problem of revocation and update of long term keys. We present an API for symmetric key management on embedded devices that supports revocation and prove security properties design in the symbolic model of cryptography. Our API supports two modes of revocation: a passive mode where keys have an expiration time, and an active mode where revocation messages are sent to devices. For the first we show that once enough time has elapsed after the compromise of a key, the system returns to a secure state, i.e. the API is robust against attempts by the attacker to use a compromised key to compromise other keys or keep the compromised key alive past its validity time. For the second we show that once revocation messages have been received the system is immediately in a secure state. Notable features of our designs are that all secret values on the device are revocable, and the device returns to a functionally equivalent state after revocation is complete.
机译:尽管广泛的研究解决了通过密码协议建立会话密钥的问题,但解决长期密钥的撤销和更新的工作却很少。我们提出了一种用于嵌入式设备上的对称密钥管理的API,该API支持撤消并在密码术的符号模型中证明安全属性设计。我们的API支持两种撤销模式:一种是被动模式,在这种模式下密钥有一个到期时间;另一种是主动模式,在这种模式下,撤销消息被发送到设备。首先,我们证明了一旦密钥泄露后经过了足够的时间,系统便会返回到安全状态,即,API具有强大的抵御能力,可防止攻击者尝试使用已泄露的密钥来泄露其他密钥或保留已泄露的密钥超过其有效时间。对于第二个示例,我们显示一旦收到吊销消息,系统将立即处于安全状态。我们设计的显着特征是设备上的所有秘密值都是可撤销的,并且撤销完成后,设备将返回功能上等效的状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号