ASICS: authenticated key exchange security incorporating certification systems.

Saved in:
Bibliographic Details
Title: ASICS: authenticated key exchange security incorporating certification systems.
Authors: Boyd, Colin1 colin.boyd@item.ntnu.no, Cremers, Cas2 cas.cremers@cs.ox.ac.uk, Feltz, Michèle3, Paterson, Kenneth4 kenny.paterson@rhul.ac.uk, Poettering, Bertram5 bertram.poettering@rhul.ac.uk, Stebila, Douglas6 stebila@qut.edu.au
Source: International Journal of Information Security. Apr2017, Vol. 16 Issue 2, p151-171. 21p.
Subjects: Computer network protocol software, Computer security, Public key infrastructure (Computer security)
Abstract: Most security models for authenticated key exchange (AKE) do not explicitly model the associated certification system, which includes the certification authority and its behaviour. However, there are several well-known and realistic attacks on AKE protocols which exploit various forms of malicious key registration and which therefore lie outside the scope of these models. We provide the first systematic analysis of AKE security incorporating certification systems. We define a family of security models that, in addition to allowing different sets of standard AKE adversary queries, also permit the adversary to register arbitrary bitstrings as keys. For this model family, we prove generic results that enable the design and verification of protocols that achieve security even if some keys have been produced maliciously. Our approach is applicable to a wide range of models and protocols; as a concrete illustration of its power, we apply it to the CMQV protocol in the natural strengthening of the eCK model to the ASICS setting. [ABSTRACT FROM AUTHOR]
Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 121700407
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: ASICS: authenticated key exchange security incorporating certification systems.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Boyd%2C+Colin%22">Boyd, Colin</searchLink><relatesTo>1</relatesTo><i> colin.boyd@item.ntnu.no</i><br /><searchLink fieldCode="AR" term="%22Cremers%2C+Cas%22">Cremers, Cas</searchLink><relatesTo>2</relatesTo><i> cas.cremers@cs.ox.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Feltz%2C+Michèle%22">Feltz, Michèle</searchLink><relatesTo>3</relatesTo><br /><searchLink fieldCode="AR" term="%22Paterson%2C+Kenneth%22">Paterson, Kenneth</searchLink><relatesTo>4</relatesTo><i> kenny.paterson@rhul.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Poettering%2C+Bertram%22">Poettering, Bertram</searchLink><relatesTo>5</relatesTo><i> bertram.poettering@rhul.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Stebila%2C+Douglas%22">Stebila, Douglas</searchLink><relatesTo>6</relatesTo><i> stebila@qut.edu.au</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22International+Journal+of+Information+Security%22">International Journal of Information Security</searchLink>. Apr2017, Vol. 16 Issue 2, p151-171. 21p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Computer+network+protocol+software%22">Computer network protocol software</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink><br /><searchLink fieldCode="DE" term="%22Public+key+infrastructure+%28Computer+security%29%22">Public key infrastructure (Computer security)</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Most security models for authenticated key exchange (AKE) do not explicitly model the associated certification system, which includes the certification authority and its behaviour. However, there are several well-known and realistic attacks on AKE protocols which exploit various forms of malicious key registration and which therefore lie outside the scope of these models. We provide the first systematic analysis of AKE security incorporating certification systems. We define a family of security models that, in addition to allowing different sets of standard AKE adversary queries, also permit the adversary to register arbitrary bitstrings as keys. For this model family, we prove generic results that enable the design and verification of protocols that achieve security even if some keys have been produced maliciously. Our approach is applicable to a wide range of models and protocols; as a concrete illustration of its power, we apply it to the CMQV protocol in the natural strengthening of the eCK model to the ASICS setting. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=121700407
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s10207-015-0312-y
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 21
        StartPage: 151
    Subjects:
      – SubjectFull: Computer network protocol software
        Type: general
      – SubjectFull: Computer security
        Type: general
      – SubjectFull: Public key infrastructure (Computer security)
        Type: general
    Titles:
      – TitleFull: ASICS: authenticated key exchange security incorporating certification systems.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Boyd, Colin
      – PersonEntity:
          Name:
            NameFull: Cremers, Cas
      – PersonEntity:
          Name:
            NameFull: Feltz, Michèle
      – PersonEntity:
          Name:
            NameFull: Paterson, Kenneth
      – PersonEntity:
          Name:
            NameFull: Poettering, Bertram
      – PersonEntity:
          Name:
            NameFull: Stebila, Douglas
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 04
              Text: Apr2017
              Type: published
              Y: 2017
          Identifiers:
            – Type: issn-print
              Value: 16155262
          Numbering:
            – Type: volume
              Value: 16
            – Type: issue
              Value: 2
          Titles:
            – TitleFull: International Journal of Information Security
              Type: main
ResultId 1