Title :
A Formal Theory of Key Conjuring
Author :
Cortier, Veronique ; Delaune, Stephanie ; Steel, Graham
Author_Institution :
CNRS & INRIA, Orsay
Abstract :
Key conjuring is the process by which an attacker obtains an unknown, encrypted key by repeatedly calling a cryptographic API function with random values in place of keys. We propose a formalism for detecting computationally feasible key conjuring operations, incorporated into a Dolev-Yao style model of the security API. We show that security in the presence of key conjuring operations is decidable for a particular class of APIs, which includes the key management API of IBM´s common cryptographic architecture (CCA).
Keywords :
application program interfaces; security of data; common cryptographic architecture; cryptographic API function; formal theory; key conjuring; Algorithm design and analysis; Computer architecture; Cryptographic protocols; Cryptography; Hardware; Informatics; Secure storage; Security; Steel;
Conference_Titel :
Computer Security Foundations Symposium, 2007. CSF '07. 20th IEEE
Conference_Location :
Venice
Print_ISBN :
0-7695-2819-8