simulatable channels
play

Simulatable Channels: Extended Security that is Universally - PowerPoint PPT Presentation

Simulatable Channels: Extended Security that is Universally Composable and Easier to Prove. ASIACRYPT 2018 J. P. Degabriele M. Fischlin 1 What this talk is about We propose and explore new security definitions for symmetric encryption


  1. Simulatable Channels: Extended Security that is Universally Composable and Easier to Prove. ASIACRYPT 2018 J. P. Degabriele M. Fischlin 1

  2. What this talk is about… • We propose and explore new security definitions for symmetric encryption based on simulation. • Our primary focus is on secure channels rather than nonce-based encryption but it could be adapted to the latter. • Conceptually interesting, non-trivial to formalise, allow simpler proofs , and imply universal composability . 2

  3. Outline of this talk • Background and Motivation • The New Definitions and Relations • SSH-CTR and Universal Composability 3

  4. Background and Motivation 4

  5. Extensions of Symmetric Encryption • Stateful Security : protects against replay and reordering of ciphertexts [BKN02, KPB03, BHMS16]. • Leakage From Invalid Ciphertexts : protects against multiple errors, release of unverified plaintext, and other forms of leakage [BDPS13, ABLMMY14, HKR14, BPS15]. • Encryption Supporting Fragmentation : encryption operating over channels which may deliver ciphertexts in a fragmented fashion [PW10, BDPS12, FGMP15, ADHP16]. 5

  6. The Price We Pay… 6

Recommend


More recommend