• DocumentCode
    1780039
  • Title

    Intercepting tokens in cryptographic protocols: The empire strikes back in the clone wars

  • Author

    Dagdelen, Ozgur ; Fischlin, Marc

  • Author_Institution
    Cryptography & Comput. Algebra, Tech. Univ. Darmstadt, Darmstadt, Germany
  • fYear
    2014
  • fDate
    June 29 2014-July 4 2014
  • Firstpage
    1529
  • Lastpage
    1533
  • Abstract
    Achieving information-theoretically secure key exchange between two parties requires some “hardware set-up”, like the possibility to transmit quantum bits. An alternative approach, which recently emerged in the crypto community, is to use tamper-resistant hardware tokens in protocols. However, such tokens need to be transmitted physically between parties, opening up the possibility to attack the actual transfer of the token, possibly in combination with attacks on the digital protocol. We discuss such interception attacks on cryptographic protocols which rely on trustworthy hardware like one-time memory tokens (Goldwasser et al., Crypto 2008). In such attacks the adversary can mount man-in-the-middle attacks and access, or even substitute, transmitted tokens. We show that many of the existing token-based protocols are vulnerable against this kind of attack, which typically lies outside of the previously considered security models. We also give a positive result for protocols remaining secure against such attacks. We present a very efficient protocol for password-based authenticated key exchange based on the weak model of one-time memory tokens. Our protocol only requires four moves, very basic operations, and the sender to send ℓ tokens in the first step for passwords of length ℓ. At the same time we achieve information-theoretic security in Canetti´s universal composition framework (FOCS 2001) against adaptive adversaries (assuming reliable erasure), even if the tokens are not guaranteed to be transferred securely, i.e., even if the adversary can read or substitute transmitted tokens.
  • Keywords
    cryptographic protocols; Canetti universal composition framework; adaptive adversaries; cryptographic protocols; digital protocol; information theoretic security; information theoretically secure key exchange; interception attack; one time memory token; password based authenticated key exchange; reliable erasure; tamper resistant hardware token; token based protocols; token interception; trustworthy hardware; weak model; Authentication; Cryptography; Hardware; Information theory; Protocols; Receivers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Theory (ISIT), 2014 IEEE International Symposium on
  • Conference_Location
    Honolulu, HI
  • Type

    conf

  • DOI
    10.1109/ISIT.2014.6875089
  • Filename
    6875089