节点文献

对“两类强壮的门限密钥托管方案”的分析

Analysis on the Two Classes of Robust Threshold Key Escrow Schemes

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 冯登国陈伟东

【Author】 FENG Deng-Guo 1) CHEN Wei-Dong 2),3) 1)(State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100080) 2)(State Key Laboratory of Information Security, Graduate School of Chinese Academy of Sciences, Beijing 100039) 3)(Institute of Electronics, Chinese Academy of Sciences, Beijing 100080)

【机构】 中国科学院软件研究所信息安全国家重点实验室中国科学院研究生院信息安全国家重点实验室 北京100080北京100039中国科学院电子学研究所北京100080

【摘要】 论文对两类“强壮”的门限密钥托管方案进行了系统分析 ,给出多种切实可行的攻击方法 ,指出它们都是不安全的 .首先 ,主要利用“可信度”函数等方法首次奠定了对密钥托管协议的形式化分析基础 .然后提出了对以上方案的两种阈下信道攻击 ,前者本质上属于“阴影会话密钥”攻击方法 ,后者则利用签名算法构造阈下信道 .通过成功实施各种欺骗攻击 ,指出两类方案并未在真正意义上解决诸如“一次监听 ,永远监听”、用户密钥碎片有效认证及鉴别恶意托管方等问题 .最后分析指出两类方案的“强壮性”值得商榷 ,并证明一些协议组件是不必要的 .

【Abstract】 Key Escrow Scheme(KES) is initially a new cryptographic idea keeping balance between protecting a person’s right to privacy and safeguarding public interests and national security in communications. Since Escrowed Encryption Standard was published by NIST in 1994, KES has been one of the focuses of attention of cryptology community. The basic method is that users communicate in the way appending LEAF(Law Enforcement Access Field,usually consisting of users’ escrowed key information) on encrypted message, by which the accredited monitor can listen in the communications. Recently two classes of new schemes,RTKES1 and RTKES2, are proposed by CAO, who declares the two ones have many good properties, such as solving the problems of “once monitor, monitor forever”, verification of users’ key shares escrowed, identifying malicious escrow agencies,resisting LEAF Feedback attacks . Especially CAO claims the schemes offer the Robustness, i.e. even the whole escrow agencies being malicious, they can not recover the key of users. In this paper,the two schemes are analyzed systematically and many practical attacks on them are provided, and the final conclusion is negative, i.e. both of them are proved to be not secure at all. First, the formalization model of KES analysis is formulated mainly based on credible degree function put forward by us for the first time. Second, authors put forward two effective subliminal channel attacks on RTKES, the former is a kind of “Shadow Session Key” attack in nature and the latter makes use of the “subliminal channel” offered by signatures. Third, by constructing “Cheating”attacks successfully,it is shown that RTKES1 and RTKES2 does not really solve the problems mentioned above. Finally, according to comprehensive theoretic analysis, authors argue whether RTKES gain their end of robustness is worth deliberating. In addition, some groupwares of RTKES are proved to be redundant or not necessary.

【基金】 国家“九七三”重点基础研究发展规划项目基金 (G1 9990 3580 2 );国家自然科学基金 (60 2 530 2 7);国家杰出青年科学基金 (60 0 2 52 0 5)资助
  • 【文献出处】 计算机学报 ,Chinese Journal of Computers , 编辑部邮箱 ,2004年09期
  • 【分类号】TN918.6
  • 【被引频次】10
  • 【下载频次】229
节点文献中: 

本文链接的文献网络图示:

本文的引文网络