Formal Security Proofs of Cryptographic Standards Cécile Baritel-Ruet

Total Page:16

File Type:pdf, Size:1020Kb

Formal Security Proofs of Cryptographic Standards Cécile Baritel-Ruet Formal Security Proofs of Cryptographic Standards Cécile Baritel-Ruet To cite this version: Cécile Baritel-Ruet. Formal Security Proofs of Cryptographic Standards. Computer Science [cs]. Université côte d’azur, 2020. English. tel-03150443 HAL Id: tel-03150443 https://tel.archives-ouvertes.fr/tel-03150443 Submitted on 23 Feb 2021 HAL is a multi-disciplinary open access L’archive ouverte pluridisciplinaire HAL, est archive for the deposit and dissemination of sci- destinée au dépôt et à la diffusion de documents entific research documents, whether they are pub- scientifiques de niveau recherche, publiés ou non, lished or not. The documents may come from émanant des établissements d’enseignement et de teaching and research institutions in France or recherche français ou étrangers, des laboratoires abroad, or from public or private research centers. publics ou privés. Preuves Formelles de la Sécurité de Standards Cryptographiques Un objectif nécessaire, possible grâce à EasyCrypt Cécile BARITEL-RUET INRIA Sophia Antipolis Présentée en vue de l’obtention du Devant le jury, composé de : grade de docteur en Informatique Manuel Barbosa, d’Université Côte d’Azur. Yves Bertot, Sandrine Blazy, Dirigée par : Yves BERTOT François Dupressoir, Co-encadrée par : Steve Kremer, Benjamin GRÉGOIRE Benjamin Grégoire, Bruno Martin Soutenue le : 02/10/2020 Preuves Formelles de la Sécurité de Standards Cryptographiques Un objectif nécessaire, possible grâce à EasyCrypt Jury : Directeurs Yves Bertot, Directeur de recherche, Inria Sophia Antipolis Méditerrannée Benjamin Grégoire, Chargé de recherche, Inria Sophia Antipolis Méditerrannée Rapporteurs Sandrine Blazy, Professeur et Chercheur, Université de Rennes 1 et IRISA Steve Kremer, Directeur de recherche, Inria Nancy Examinateurs Manuel Barbosa, Lecturer and Researcher, University of Porto and HASLab François Dupressoir, Senior Lecturer, University of Bristol Bruno Martin, Professeur et Chercheur, Université Côte d’Azur et I3S Formal Security Proofs of Cryptographic Standards A necessity achieved using EasyCrypt Jury : Advisors Yves Bertot, Research director, Inria Sophia Antipolis Méditerrannée Benjamin Grégoire, Researcher, Inria Sophia Antipolis Méditerrannée Rapporteurs Sandrine Blazy, Lecturer and Researcher, Université de Rennes 1 and IRISA Steve Kremer, Research director, Inria Nancy Examiners Manuel Barbosa, Lecturer and Researcher, University of Porto and HASLab François Dupressoir, Senior Lecturer, University of Bristol Bruno Martin, Lecturer and Researcher, Université Côte d’Azur et I3S Titre : Preuves Formelles de la Sécurité de Standards Cryptographiques Résumé : En cryptographie, Shannon a montré que le secret parfait n’existe pas. Ainsi, la cryp- tographie moderne considère des propriétés de sécurité dans lesquelles un attaquant peut briser l’algorithme cryptographique mais seulement avec une faible probabilité. Dans ce contexte, les algorithmes cryptographiques et les propriétés/hypothèses de sécurité sont ex- primés sous forme de programmes probabilistes. Les preuves de sécurité consistent à borner la probabilité d’un événement dans de tels programmes. Ces preuves sont difficiles à prou- ver et malgré le système de relecture académique des erreurs continuent d’être publiées. Nous proposons l’utilisation des preuves formelles pour assurer une fiabilité suffisante des standards cryptographiques. Ma thèse fournit les preuves formelles de sécurité de trois standards dans l’assistant de preuve EasyCrypt. Ces schémas sont CMAC (qui fournit l’authentification et l’intégrité des messages), SHA-3 (une fonction de hachage cryptographique), et ChaCha20-Poly1305 (un schéma de chiffrement authentifié avec données associées). L’objectif de la thèse n’est pas seulement de formaliser la preuve de sécurité de ces standards, mais aussi de développer des techniques génériques et des bibliothèques qui peuvent être réutilisées. Toutefois, les preuves formelles de sécurité n’assurent que la sécurité des algorithmes et non de leurs implémentations. Pour contourner cette lacune, avec mes collaborateurs, nous lions formel- lement nos implémentations sûres et efficaces avec la preuve de sécurité, ceci conduit à la première preuve de sécurité cryptographique d’implémentations. Mots clés : Cryptographie, Standards, Sécurité prouvable, EasyCrypt, Preuve formelle, CMAC, SHA-3, ChaCha20-Poly1305. ix Title: Formal Security Proofs of Cryptographic Standards Abstract: In cryptography, Shannon showed that perfect secrecy does not exist. Thus, modern cryptography considers security properties in which attackers may break the cryptographic algorithm only with a small (negligible) probability. In this context, cryptographic algo- rithms and security properties/assumptions are expressed as probabilistic programs. Secu- rity proofs consist of bounding the probability of an event in such programs. Such proofs have been peer-reviewed for some decades, but since they are difficult to prove and to verify, fallacies keep emerging. We propose to use formal proofs to provide enough trustworthiness for crypto-systems such as cryptographic standards. My thesis provides the formal security proofs of three standards that are formally verified using the proof assistant EasyCrypt. The cryptographic standards I have worked on are CMAC (that provides message authentication and integrity), SHA-3 (a cryptographic hash function), and ChaCha20-Poly1305 (an authenticated encryption scheme with associated data). The goal of the thesis is not only to provide formal proof of those standards, but also to develop generic techniques and libraries that can be reused. However, the formal security proofs only ensure the security of the algorithms and not its implementation. To circumvent this gap, with my collaborators, we have developed fast and secure implementations of the last two schemes that are also side-channel resistant. Furthermore, we formally link the implementation with the security proof, leading to the first formal security proof of an implementated standard. Keywords: Cryptography, Standards, Provable security, EasyCrypt, Formal proof, CMAC, SHA-3, ChaCha20-Poly1305. Remerciements — Acknowledgements Je souhaite remercier en tout premier lieu mes deux directeurs, Yves Bertot et Benjamin Grégoire, pour leur temps, leur soutien et leurs conseils que vous avez su m’offrir pendant ces quatre années de travail ensemble. Merci à toi Benjamin pour le soutien indéfectible et la bienveillance que tu as su témoi- gner durant notre travail ensemble. Merci de m’avoir posé toutes ces questions auxquelles je ne savais pas répondre immédiatement, m’enseignant beaucoup et en particulier cette compétence fort utile qu’est la prise de recul. Je te suis reconnaissante pour tes efforts de relecture, que j’espère savoir apprécier à leur juste valeur. Merci à toi Yves pour ton humanité, tes conseils et ton écoute pendant toute la durée de ma thèse. Malgré la différence dans nos domaines d’expertise respectifs, nos échanges ont toujours été non seulement enrichissant, mais aussi ont contribué à la prise de recul sur mon domaine de recherche et le domaine de la recherche de manière générale. Plus particulièrement, merci pour ton soutien pendant ce confinement de mars à mai 2020. I want to humbly thank my jury for accepting to review my work. In particular, I am wholeheartedly grateful to both Sandrine Blazy and Steve Kremer, who dared to be rapporteurs, even though the health crisis and the summer break would leave them little time to read this manuscript and write their report. Thank you, François Dupressoir, Manuel Barbossa, and Bruno Martin for showing enough interest in my work to participate in this jury. Je tiens à remercier tous les membres de l’équipe Marelle — maintenant l’équipe Stamp — qu’ils soient permanents ou non. L’ambiance que vous avez su maintenir est à la hauteur du temps de la région : chaleureuse, agréable et humaine. Merci Laurence, pour ta gen- tillesse, tes conseils, ta bienveillance et ton énergie. Merci à Laurent pour ses conseils sur l’Agreg, même si je ne souhaite plus m’y diriger. Merci à Reynald pour toutes les inspirations que tu m’as données à propos de la constitution de ces remerciements. Merci à Sophie et Damien pour ces discussions entre doctorants toujours très intéressantes et enrichissantes, notamment sur l’éducation. Thank you, Anders, for the pleasant co-habitation at the office. Merci à Mohammad et Adam pour la bonne humeur qu’ils ont instaurée dans le bureau. Merci à Pierre pour ces discussions autour d’un (un ?) café. Merci à Cyril pour son point de vue rafraichissant et bienveillant. Merci à Maxime et Enrico pour avoir animé les repas du midi. Merci à Nathalie pour son soutien, son humanité, sa bonne humeur et sa bienveillance. Son travail nous soulage d’un poids administratif et je pense ne pas savoir mesurer son im- portance tant elle fait bien son travail pour qu’on ne le remarque pas. Merci pour sa trilogie, que j’attends avec impatience en version électronique. Je souhaite rendre hommage à José qui nous a quitté en 2019, on pense à lui. xii Remerciements — Acknowledgements Merci à tous ceux qui ont bien voulu m’écouter parler de ma recherche. Je tiens notam- ment à remercier les deux membres de mon comité de suivi doctoral, François Dupressoir et Cinzia Di Guisto, pour vos retours, vos encouragements et vos éclairements. Merci aux enseignants Cinzia Di Guisto, Sid Touati et Étienne Lozes, pour m’avoir permis de travailler avec vous pour mon service en tant que chargé de TP/TD. Je tiens aussi à remercier mes élèves
Recommended publications
  • FIPS 140-2 Non-Proprietary Security Policy
    Kernel Crypto API Cryptographic Module version 1.0 FIPS 140-2 Non-Proprietary Security Policy Version 1.3 Last update: 2020-03-02 Prepared by: atsec information security corporation 9130 Jollyville Road, Suite 260 Austin, TX 78759 www.atsec.com © 2020 Canonical Ltd. / atsec information security This document can be reproduced and distributed only whole and intact, including this copyright notice. Kernel Crypto API Cryptographic Module FIPS 140-2 Non-Proprietary Security Policy Table of Contents 1. Cryptographic Module Specification ..................................................................................................... 5 1.1. Module Overview ..................................................................................................................................... 5 1.2. Modes of Operation ................................................................................................................................. 9 2. Cryptographic Module Ports and Interfaces ........................................................................................ 10 3. Roles, Services and Authentication ..................................................................................................... 11 3.1. Roles .......................................................................................................................................................11 3.2. Services ...................................................................................................................................................11
    [Show full text]
  • Critical Perspectives on Provable Security: Fifteen Years of “Another Look” Papers
    Advances in Mathematics of Communications doi:10.3934/amc.2019034 Volume 13, No. 4, 2019, 517{558 CRITICAL PERSPECTIVES ON PROVABLE SECURITY: FIFTEEN YEARS OF \ANOTHER LOOK" PAPERS Neal Koblitz Department of Mathematics University of Washington, USA Alfred Menezes Department of Combinatorics & Optimization University of Waterloo, Canada Abstract. We give an overview of our critiques of \proofs" of security and a guide to our papers on the subject that have appeared over the past decade and a half. We also provide numerous additional examples and a few updates and errata. 1. Introduction What does \provable security" mean? If \proof" is understood in the strict mathematical sense | as in \proof of the Pythagorean Theorem" or \proof of Fermat's Last Theorem" | then there's a simple answer: There is no such thing. \Provable security" is an oxymoron. As Benjamin Franklin said 230 years ago, \in this world nothing can be said to be certain, except death and taxes." About communications security there can be no certainty. But it is wrong to reject proofs in cryptography just because in general they do not measure up to the standards of pure mathematics. To take such an inflexible position would be, as Jonathan Katz pointed out, \snobbery at its purest" [200]. Proofs can be useful in several ways. They enforce a kind of discipline on authors so that they strive for precision, systematic approaches, and completeness. They rule out certain categories of attacks or attacks on certain parts of the protocol so that testing can focus on other types of attacks and on the assumptions made in the provable security theorem.
    [Show full text]
  • The Missing Difference Problem, and Its Applications to Counter Mode
    The Missing Difference Problem, and its Applications to Counter Mode Encryption? Ga¨etanLeurent and Ferdinand Sibleyras Inria, France fgaetan.leurent,[email protected] Abstract. The counter mode (CTR) is a simple, efficient and widely used encryption mode using a block cipher. It comes with a security proof that guarantees no attacks up to the birthday bound (i.e. as long as the number of encrypted blocks σ satisfies σ 2n=2), and a matching attack that can distinguish plaintext/ciphertext pairs from random using about 2n=2 blocks of data. The main goal of this paper is to study attacks against the counter mode beyond this simple distinguisher. We focus on message recovery attacks, with realistic assumptions about the capabilities of an adversary, and evaluate the full time complexity of the attacks rather than just the query complexity. Our main result is an attack to recover a block of message with complexity O~(2n=2). This shows that the actual security of CTR is similar to that of CBC, where collision attacks are well known to reveal information about the message. To achieve this result, we study a simple algorithmic problem related to the security of the CTR mode: the missing difference problem. We give efficient algorithms for this problem in two practically relevant cases: where the missing difference is known to be in some linear subspace, and when the amount of data is higher than strictly required. As a further application, we show that the second algorithm can also be used to break some polynomial MACs such as GMAC and Poly1305, with a universal forgery attack with complexity O~(22n=3).
    [Show full text]
  • On Comparing Side‑Channel Properties of AES and Chacha20 on Microcontrollers
    This document is downloaded from DR‑NTU (https://dr.ntu.edu.sg) Nanyang Technological University, Singapore. On comparing side‑channel properties of AES and ChaCha20 on microcontrollers Najm, Zakaria; Jap, Dirmanto; Jungk, Bernhard; Picek, Stjepan; Bhasin, Shivam 2018 Najm, Z., Jap, D., Jungk, B., Picek, S., & Bhasin, S. (2018). On comparing side‑channel properties of AES and ChaCha20 on microcontrollers. 2018 IEEE Asia Pacific Conference on Circuits and Systems (APCCAS). doi:10.1109/APCCAS.2018.8605653 https://hdl.handle.net/10356/104628 https://doi.org/10.1109/APCCAS.2018.8605653 © 2018 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. The published version is available at: https://doi.org/10.1109/APCCAS.2018.8605653 Downloaded on 30 Sep 2021 18:00:37 SGT On Comparing Side-channel Properties of AES and ChaCha20 on Microcontrollers Zakaria Najm1,2, Dirmanto Jap1, Bernhard Jungk3, Stjepan Picek2, and Shivam Bhasin1 1Temasek Laboratories, Nanyang Technological University, Singapore 2Delft University of Technology, Delft, The Netherlands 3Independent Researcher fzakaria.najm,djap,[email protected], bernhard@projectstarfire.de, [email protected] Abstract—Side-channel attacks are a real threat to many secure When considering countermeasures, it is also the nonlinear systems. In this paper, we consider two ciphers used in the operation which is expensive to implement protected against automotive industry – AES and ChaCha20 and we evaluate their side-channel attacks, unlike other linear components of the resistance against side-channel attacks.
    [Show full text]
  • Stream Cipher Designs: a Review
    SCIENCE CHINA Information Sciences March 2020, Vol. 63 131101:1–131101:25 . REVIEW . https://doi.org/10.1007/s11432-018-9929-x Stream cipher designs: a review Lin JIAO1*, Yonglin HAO1 & Dengguo FENG1,2* 1 State Key Laboratory of Cryptology, Beijing 100878, China; 2 State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China Received 13 August 2018/Accepted 30 June 2019/Published online 10 February 2020 Abstract Stream cipher is an important branch of symmetric cryptosystems, which takes obvious advan- tages in speed and scale of hardware implementation. It is suitable for using in the cases of massive data transfer or resource constraints, and has always been a hot and central research topic in cryptography. With the rapid development of network and communication technology, cipher algorithms play more and more crucial role in information security. Simultaneously, the application environment of cipher algorithms is in- creasingly complex, which challenges the existing cipher algorithms and calls for novel suitable designs. To accommodate new strict requirements and provide systematic scientific basis for future designs, this paper reviews the development history of stream ciphers, classifies and summarizes the design principles of typical stream ciphers in groups, briefly discusses the advantages and weakness of various stream ciphers in terms of security and implementation. Finally, it tries to foresee the prospective design directions of stream ciphers. Keywords stream cipher, survey, lightweight, authenticated encryption, homomorphic encryption Citation Jiao L, Hao Y L, Feng D G. Stream cipher designs: a review. Sci China Inf Sci, 2020, 63(3): 131101, https://doi.org/10.1007/s11432-018-9929-x 1 Introduction The widely applied e-commerce, e-government, along with the fast developing cloud computing, big data, have triggered high demands in both efficiency and security of information processing.
    [Show full text]
  • Deriving Chacha20 Key Streams from Targeted Memory Analysis
    Deriving ChaCha20 Key Streams From Targeted Memory Analysis Peter McLaren, William J Buchanan, Gordon Russell, Zhiyuan Tan School of Computing, Edinburgh Napier University, Edinburgh, UK. Abstract—There can be performance and vulnerability con- keys without impacting the target and for target applications cerns with block ciphers, thus stream ciphers can used as an alter- to be unaware of extraction. native. Although many symmetric key stream ciphers are fairly The rest of the paper is structured as follows. Section II resistant to side-channel attacks, cryptographic artefacts may exist in memory. This paper identifies a significant vulnerability discusses related research including side-channel studies and within OpenSSH and OpenSSL and which involves the discovery background on stream ciphers and ChaCha20 cipher imple- of cryptographic artefacts used within the ChaCha20 cipher. This mentations is presented in Section III. Section IV provides can allow for the cracking of tunneled data using a single targeted relevant details of the framework and its implementation is memory extraction. With this, law enforcement agencies and/or given in Section V. The results are presented and discussed in malicious agents could use the vulnerability to take copies of the encryption keys used for each tunnelled connection. The Section VI and conclusions drawn in Section VII. user of a virtual machine would not be alerted to the capturing of the encryption key, as the method runs from an extraction II. RELATED WORK of the running memory. Methods of mitigation include making This paper focuses on the decrypting network traffic en- cryptographic artefacts difficult to discover and limiting memory crypted with ChaCha20-Poly1305 cipher.
    [Show full text]
  • Optimizing Authenticated Encryption Algorithms
    Masaryk University Faculty of Informatics Optimizing authenticated encryption algorithms Master’s Thesis Ondrej Mosnáček Brno, Fall 2017 Masaryk University Faculty of Informatics Optimizing authenticated encryption algorithms Master’s Thesis Ondrej Mosnáček Brno, Fall 2017 This is where a copy of the official signed thesis assignment and a copy ofthe Statement of an Author is located in the printed version of the document. Declaration Hereby I declare that this paper is my original authorial work, which I have worked out on my own. All sources, references, and literature used or excerpted during elaboration of this work are properly cited and listed in complete reference to the due source. Ondrej Mosnáček Advisor: Ing. Milan Brož i Acknowledgement I would like to thank my advisor, Milan Brož, for his guidance, pa- tience, and helpful feedback and advice. Also, I would like to thank my girlfriend Ludmila, my family, and my friends for their support and kind words of encouragement. If I had more time, I would have written a shorter letter. — Blaise Pascal iii Abstract In this thesis, we look at authenticated encryption with associated data (AEAD), which is a cryptographic scheme that provides both confidentiality and integrity of messages within a single operation. We look at various existing and proposed AEAD algorithms and compare them both in terms of security and performance. We take a closer look at three selected candidate families of algorithms from the CAESAR competition. Then we discuss common facilities provided by the two most com- mon CPU architectures – x86 and ARM – that can be used to implement cryptographic algorithms efficiently.
    [Show full text]
  • Primus HSM E-Series
    The affordable hardware security module Primus HSM E-Series Market-leading price-performance ratio HSM Network Appliance as a replacement for PCIe cards Simple setup, configuration, and maintenance Tamper protection during transport, storage, and operation Scalable and flexible partitionable to your needs Designed, developed, and manufactured in Switzerland The E-Series of our Primus HSM offers high performance at an outstanding price. Connecting the devices to existing systems is just as easy as commissioning. Different performance classes The E-Series is available in various performance classes: E20, E60 and E150. It can be configu- red via the serial port or over the network with our Decanus remote terminal. Applications The devices of the E-Series are very versatile. Built as network appliances, they lack the disad- vantages of PCIe-based solutions like software dependance of PCIe host systems and the host system itself. The E-Series is ideally suited to secure financial transactions such as EBICS and PCI, access to the cloud (CASB), key management in the PKI environment, or to protect blockchain systems, crypto assets management. Functions The devices generate encryption keys, store and manage the distribution of these keys. Besides key management, they also perform authentication and encryption tasks. Multiple Primus HSM can be grouped together to support redundancy and load balancing. Each Primus HSM can also be partitioned for multiple users (multi-tenancy). Primus supports symmetric (AES, Camellia), asymmetric (RSA, ECC, Diffie-Hellman), and hashing (SHA-2, SHA-3) cryptographic algorithms. They can be seamlessly and easily integrated into any network environment. The Primus E-Se- ries HSM can be remote controlled with our Decanus Remote Control Terminal.
    [Show full text]
  • Chacha20 and Poly1305 Cipher Suites for TLS
    ChaCha20 and Poly1305 Cipher Suites for TLS Adam Langley Wan-Teh Chang Outline ● ChaCha20 stream cipher ● Poly1305 authenticator ● ChaCha20+Poly1305 AEAD construction ● TLS cipher suites ● Performance ChaCha20 stream cipher ● Designed by Dan J. Bernstein ● A variant of Salsa20 to improve diffusion ● Used in BLAKE, a SHA-3 finalist ● 256-bit key ● 64-bit nonce ● 64-bit block counter ● Outputs a 64-byte block of key stream and increments block counter in each invocation ● Plaintext is XOR’ed with the key stream ChaCha20 function constants key counter nonce Input S0 S1 S2 S3 S4 S5 S6 S7 State (16 words) S8 S9 S10 S11 S12 S13 S14 S15 Output key stream (64 bytes) Poly1305 authenticator ● A Wegman-Carter, one-time authenticator ● Designed by Dan J. Bernstein ● 256-bit key ● 128-bit output Poly1305 calculation Key (r, s): r => integer R, s => integer S Input is divided into 16-byte chunks C0 C1 C2 C3 C4 C5 . Cn-2 Cn-1 C0*R^n + C1*R^(n-1) + C2*R^(n-2) + … + Cn-2*R^2 + Cn-1*R mod (2^130- 5) Evaluate this polynomial with Horner’s Rule + S mod 2^128 AEAD construction ● The AEAD key is a ChaCha20 key ● For each nonce, derive: Poly1305 key = ChaCha20(000...0, counter=0) Discard the last 32 bytes of output ● A = additional data ● S = ChaCha20(plaintext, counter=1) ● T = Poly1305(A || len(A) || S || len(S)) ● Ciphertext = S || T TLS cipher suites ● Three forward secret, AEAD ciphers: ○ TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ○ TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 ○ TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ● No implicit nonce: fixed_iv_length
    [Show full text]
  • Security Protocols in a Nutshell
    Security Protocols in a Nutshell Mohsen Toorani Department of Informatics University of Bergen, Norway [email protected] Abstract Security protocols are building blocks in secure communications. They deploy some security mechanisms to provide certain security services. Security protocols are considered abstract when analyzed, but they can have extra vulnerabilities when implemented. This manuscript provides a holistic study on security protocols. It reviews foundations of security protocols, taxonomy of attacks on security protocols and their implementations, and different methods and models for security analysis of protocols. Specifically, it clarifies differences between information-theoretic and computational security, and computational and symbolic models. Furthermore, a survey on computational security models for authenticated key exchange (AKE) and password-authenticated key exchange (PAKE) protocols, as the most impor- tant and well-studied type of security protocols, is provided. Keywords: Cryptographic protocols, Authenticated key exchange, Computational security, Provable security, Security models. arXiv:1605.09771v2 [cs.CR] 2 Jun 2016 Copyright c 2015 Mohsen Toorani. All Rights Reserved. Contents 1 Introduction 1 1.1 Security attacks . 2 1.2 Security services . 2 1.3 Security mechanisms . 3 2 Taxonomy of attacks 3 2.1 Attacks on security protocols . 3 2.2 Attacks on encryption schemes . 8 2.3 Attacks on implementations . 11 3 Security models 14 3.1 Information-theoretic vs computational security . 15 3.2 Idealized models in computational security . 16 3.3 Formal security models . 18 3.4 Security proofs in reality . 19 4 Security models for cryptographic protocols 20 4.1 AKE protocols . 22 4.1.1 Security models for AKE protocols . 23 4.1.2 PAKE protocols .
    [Show full text]
  • Mackerel: a Progressive School of Cryptographic Thought
    Mackerel: A Progressive School of Cryptographic Thought JUSTIN TrOUTMAN AND VINceNT RIjmeN Justin Troutman is a Troutman and Rijmen offer a framework for creating and fielding new security systems involving cryptography. Without this or a similar framework to coordinate efforts between different stake- cryptographer with research holder communities, we are doomed to continue providing systems that provide less than expected, interests in designing take too long from conceptual birth to fielding, and still leave us at unacceptable risk. authenticated encryption Their framework is “chunked” to nicely fit the natural flow of effort from cryptographers to develop- constructions, optimizing the ers to users; this allows each profession to maximize its strengths and not be unnecessarily befud- user experience of cryptographic products, and dled by work going on in sister professions that are also needed to complete full delivery of effective analyzing methodologies for signals intelligence. systems—systems that can be deployed and safely used by customers with minimal training. He has worked with Microsoft, Google, Duke Is this work perfect and fully fleshed out? NO. Is it a big step in the right direction? I think YES! Read University, and IEEE. He co-developed the and enjoy; it is an easy read that should plant interesting concepts in your mind that will take root “green cryptography” strategy for minimizing and grow, leading to further needed developments. implementation complexity, while maximizing —Brian Snow, former Technical Director of Information Assurance at NSA. cryptographic security, by recycling components for multiple purposes. He is currently organizing ryptography is hard, but it’s the easy part.
    [Show full text]
  • Securing Hardware, Software and Data (SHSD) • Frank Siebenlist, Argonne National Laboratory • Len Napolitano, Sandia National Laboratories
    Report of the Cyber Security Research Needs for Open Science Workshop July 23-24, 2007 Sponsored by the DOE Office of Science in Cooperation with the Office of Electricity Delivery and Energy Reliability PNNL-16971 Report of the Cyber Security Research Needs for Open Science Workshop July 23-24, 2007 Sponsored by the DOE Office of Science in Cooperation with the Office of Electricity Delivery and Energy Reliability i Acknowledgements The workshop chairs wish to thank Joree O’Neal and Rachel Smith for all their help and support with organizing the logistics and registration activities for this workshop; Sue Chin, Ted Tanasse, Barbara Wilson, and Stacy Larsen for their expert help with the assembly, text editing, and graphics for this report; and Lance Baatz for his masterful job as webmaster for this project. Finally, we wish to thank the Pacific Northwest National Laboratory for supporting the development and assembly of the final report. iii EXECUTIVE SUMMARY Protecting systems and users, while maintaining ease of access, represents the “perfect storm” of challenges in the area of cyber security. A fundamental tenet of every scientific investigation is the search for truth. Trust and integrity are immutable values that are fundamental to all research endeavors. By extension, the absolute integrity of information, encompassing systems, networks, and file systems is a critical requirement essential for promoting and facilitating discovery. These qualities are equally important for our nation’s critical energy infrastructure. To determine the cyber security research needs for open science and energy control systems, the U.S. Department of Energy’s (DOE) Office of Science (SC), in cooperation with the Office of Electricity Delivery and Energy Reliability (OE), organized a two-day workshop held July 23 and 24, 2007, at the Bethesda North Marriott Hotel in Bethesda, Maryland.
    [Show full text]