Security Model for Authenticated Key Exchange, Reconsidered
摘要
Authenticated key exchange (AKE) is a fundamental cryptographic protocol that establishes a secure channel over the Internet. The security for AKE is defined as a security game between an adversary and the challenger. Especially, partners and freshness of the session are used to identify trivial attacks by the adversary. Roughly, partners are instances that derive the same session key, and freshness determines whether an adversary’s behavior constitutes trivial attacks. In this work, we reconsider security definitions for AKE and point out the shortcomings of the conventional partners and freshness definition. Then, we propose a new robust and strong security definition. First, we propose a new definition of partners based on round identifiers. Second, we propose a new freshness definition, which captures more non-trivial attacks than the conventional ones. We introduce a new notion of miscommunicators to identify the adversary’s behavior more accurately than conventional definitions. This allows, for example, the behavior of sending the first message as-is and tampering with the second message to be viewed as a non-trivial attack, which was considered a trivial attack in conventional definitions. Our new security definition is strictly stronger than the conventional one. As evidence of this, we provide a new construction of AKE that is secure in the conventional definition but insecure in the new definition.