节点文献
阈下信道技术研究
Study on Subliminal Channels
【作者】 董庆宽;
【导师】 肖国镇;
【作者基本信息】 西安电子科技大学 , 密码学, 2003, 博士
【摘要】 阈下信道是指在基于公钥密码技术的数字签名、认证等应用密码体制的输出密码数据中建立起来的一种隐蔽信道,除指定的接收者外,任何其他人均不知道密码数据中是否有阈下消息存在。它是一种典型的现代信息隐藏技术,有着广阔的应用前景。本文对阈下信道技术进行了比较全面的总结和研究,包括阈下信道的发展状况,应用前景,阈下信道的模型,构造方法,隐匿密钥,容量,安全性以及封闭方法等。 作者在本文中主要取得的研究结果如下: 1.给出了阈下信道系统的一般模型和宿主密码系统须满足的必要条件,首次定义了阈下信道中的秘密信道与攻击信道,并给出关于安全性的基本结论,首次定义了对容量和安全性有一定影响的嵌入成功率和信道使用率两个新参数。 2.基于不同构造机理对阈下信道进行了分类,设计了基于代理签名的新型宽带阈下信道,减小了原始签名人权限被滥用的风险,设计了部分陷门密钥泄漏与搜索相结合的具有较大容量的新型窄带阈下信道,分折了认证码中构造阈下信道无实际意义的原因并对被滥用系统和含阈下信道系统的概念给予了区分。 3.首次对阈下信道中的隐匿密钥协商的概念、实现条件和基本协议进行了讨论,并设计了已知秘密的隐匿密钥协商方案和几个未知秘密的隐匿密钥协商方案。 4.给出了容量的定义,理论上界以及影响容量的几个因素,给出了嵌入成功率和信道使用率对容量的影响,研究了ElGamal签名中宽带信道的容量,分析了18种广义ElGamal签名中的宽带阈下信道的容量并指出了最优方案,具体研究了基于搜索的窄带信道的容量与嵌入成功率的关系,具体研究了牛顿信道的带宽。 5.给出了一次使用信道的安全条件,研究了随机性的统计检测方法,主要是贝努利试验二项分布情况下的统计检测,给出了基于相对熵的假设检验模型下关于多次使用信道安全性的一些结果。 6.总结了封闭阈下信道的若干方法并对各方案优缺点进行了对比分析,给出了作为系统输入的无害消息的语义随机性不可能完全封闭的结论,设计了新的对ElGamal类签名中会话密钥进行完全封闭的方案,讨论了现有封闭方案的实用性。
【Abstract】 A subliminal channel is a covert communication channel to send a message to an authorized receiver. This channel is constructed in the output crypto-data of an applied public-key cryptosystem such as digital signature, authentication, and so on. The message can not be discovered by any unauthorized receivers. It can be used in many practical applications as a representative information hiding technology. In this dissertation we make a study of subliminal channels that conclude the progress, the application, the model, the construction, the stego-key, the capacity, the security, the way to realize subliminal-freeness, and so on.The main results we have obtained in this dissertation are as follows:1. A general model of subliminal channels and some necessary conditions that the carrier cryptosystem must holds are given. A secret channel and an attack channel are first defined and some basic conclusions of the security are given. Two new parameters, the Embedding Rate and the Channel-Using Rate, that have large effects on the capacity and the security of subliminal channels are first defined.2. The subliminal channels available are classified according to the construction mechanism. A new broadband channel is designed in proxy signatures to reduce the risk of the original signer’s signing capability being abused. A new narrowband channel with large capacity is designed based on a combination of the leaks of partial trapdoor key and the exhausting search. The reasons for the meaningless -ness in practical of the construction of a subliminal channel in authentication codes are analyzed. An abused system and a subliminal system are distinguished.3. The concept of stego-key exchange is first presented. Some conditions and a basic protocol of realizing it are first discussed. Then a known-secret stego-key exchange scheme and some unknown-secret stego-key exchange schemes are designed.4. The subliminal capacity is defined. A theoretical upper bound of the capacity and some factors that reduce the capacity are given. The effects of the Channel-Used Rate and the Embedding Rate on subliminal capacity are also given. The capacity of subliminal channels in ElGamal signatures is studied. The capacity of broadband channel and the optimal schemes in 18 general ElGamal signatures are analyzed. The relation between the capacity and the Embedding Rate of narrowband subliminal channels based on the exhausting search is studied. We also studied the capacity of Newton channel.5. The security conditions of one-time-used channels are given. The probabilistic detection of subliminal channels mainly under Bernoulli test with binomial distribution is studied. Some results of the security of many-time-used channels in hypothesis test model based on relative entropy are obtained.6. The schemes to avoid the subliminal channels are summarized and compared with each other. A conclusion is drawn that the subliminal channel introduced by the semantic randomness of the input harmless message of cryptosystem can not be completely avoided. A new scheme to generate ELGamal-type signatures that are free of any subliminal channels introduced by its session key is designed. The practicability of the subliminal-free protocols available is discussed.
【Key words】 Subliminal Channel; Digital Signature; Cryptography; Information Hiding;