Author
|
Conference
|
Journal
|
Organization
|
Year
|
DOI
Look for results that meet for the following criteria:
since
equal to
before
between
and
Search in all domains
Limit my searches in the following domains
Agriculture Science
Arts & Humanities
Biology
Chemistry
Computer Science
Economics & Business
Engineering
Environmental Sciences
Geosciences
Material Science
Mathematics
Medicine
Physics
Social Science
Multidisciplinary
Keywords
(4)
Key Agreement Protocol
Key Establishment
Public Key
Security Model
Subscribe
Academic
Publications
Reusing Static Keys in Key Agreement Protocols
Edit
Reusing Static Keys in Key Agreement Protocols
(
Citations: 3
)
BibTex
|
RIS
|
RefWorks
Download
Sanjit Chatterjee
,
Alfred Menezes
,
Berkant Ustaoglu
Contrary to conventional cryptographic wisdom, the NIST SP 800-56A standard ex- plicitly allows the use of a static key pair in more than one of the
key establishment
protocols described in the standard. In this paper, we give examples of
key establishment
protocols that are individually secure, but which are insecure when static key pairs are reused in two of the protocols. We also propose an enhancement of the extended Canetti-Krawczyk
security model
and definition for the situation where static public keys are reused in two or more
key agreement
protocols.
Conference:
International Conference on Cryptology - INDOCRYPT
, pp. 39-56, 2009
DOI:
10.1007/978-3-642-10628-6_3
Cumulative
Annual
View Publication
The following links allow you to view full publications. These links are maintained by other sources not affiliated with Microsoft Academic Search.
(
www.springerlink.com
)
(
www.springerlink.com
)
(
www.cacr.math.uwaterloo.ca
)
(
www.math.uwaterloo.ca
)
(
www.cacr.math.uwaterloo.ca
)
(
dx.doi.org
)
(
www.informatik.uni-trier.de
)
More »
Citation Context
(3)
...Recent work studied the effect of reusing static key pairs among different key agreement protocols [
4
]...
...Note that such reuse is explicitly allowed by the NIST standard [12], but can lead to a Combined Security Analysis of the One- and Three-Pass UM 59 security vulnerability [
4
]...
...In fact, this is precisely the attack scenario that was considered in [
4
]...
...To circumvent the protocol interference attack of [
4
] on one- and three-pass UM in the combined model, one-pass UM (see §3.2) is modified by including the protocol identifier UM1 (in addition to the ephemeral public key X )i n the optional input Λ to the key derivation function...
Sanjit Chatterjee
,
et al.
Combined Security Analysis of the One and Three-Pass Unified Model Key...
...This is a little surprising since the KAS1 and KAS2 protocols have noticeably different security attributes and, as observed in [
6
], interference attacks on the runs of two protocols can render one of the protocols insecure...
Sanjit Chatterjee
,
et al.
A Generic Variant of NIST’s KAS2 Key Agreement Protocol
...Even if static keys are shared only among key agreement protocols, security is not necessarily guaranteed as exposed in [
6
]...
...Recently, Chatterjee, Menezes, and Ustao˘ glu [
6
] showed that Bob’s static information use influences security of session keys at Alice should Alice and Bob engage in sessions...
...In our proposal, we explicitly consider four protocol types: between parties that use ID-based algorithms, parties that use certificates, and the mixture of the two. 2 As said, [
6
] dem-...
...Remark The model is extension of the combined model presented in [
6
], which in turn is based on the model presented in [17]...
Berkant Ustaoğlu
.
Integrating identity-based and certificate-based authenticated key exc...
References
(21)
Robustness Principles for Public Key Protocols
(
Citations: 133
)
Ross J. Anderson
,
Roger M. Needham
Conference:
International Crytology Conference - CRYPTO
, pp. 236-247, 1995
Key Agreement Protocols and Their Security Analysis
(
Citations: 203
)
Simon Blake-wilson
,
Don Johnson
,
Alfred Menezes
Conference:
IMA Conference on Cryptography and Coding
, pp. 30-45, 1997
Identity-Based Encryption from the Weil Pairing
(
Citations: 2277
)
Dan Boneh
,
Matthew K. Franklin
Conference:
International Crytology Conference - CRYPTO
, pp. 213-229, 2001
Efficient One-Round Key Exchange in the Standard Model
(
Citations: 24
)
Colin Boyd
,
Yvonne Cliff
,
Juan Gonzalez Nieto
,
Kenneth G. Paterson
Conference:
Australasian Conference on Information Security and Privacy - ACISP
, pp. 69-83, 2008
Analysis of Key-Exchange Protocols and Their Use for Building Secure Channels
(
Citations: 331
)
Ran Canetti
,
Hugo Krawczyk
Conference:
Theory and Application of Cryptographic Techniques - EUROCRYPT
, pp. 453-474, 2001
Order by:
Citations
(3)
Combined Security Analysis of the One and Three-Pass Unified Model Key Agreement Protocols
(
Citations: 1
)
Sanjit Chatterjee
,
Alfred Menezes
,
Berkant Ustaoglu
Conference:
International Conference on Cryptology - INDOCRYPT
, pp. 49-68, 2010
A Generic Variant of NIST’s KAS2 Key Agreement Protocol
Sanjit Chatterjee
,
Alfred Menezes
,
Berkant Ustaoglu
Integrating identity-based and certificate-based authenticated key exchange protocols
Berkant Ustaoğlu