Secure Key Exchange via Transparent Reverse Firewalls
摘要
In this work, we study secure authenticated key exchange (AKE) protocols in a scenario where an adversary subverts the implementation of honest parties in an undetectable manner, thereby gaining access to confidential information. Mironov and Stephens-Davidowitz (EUROCRYPT 2015) introduced the concept of reverse firewalls to counteract such a subversion attack. Subsequently, Dodis et al. (CRYPTO 2016) proposed an AKE protocol that supports transparent reverse firewalls, where the reverse firewalls are undetectable by both parties involved in the protocol. They proved the security of their protocol in a specific AKE model defined by themselves. In this paper, we present a negative finding regarding the construction of subversion-resilient AKE protocols with reverse firewalls. We demonstrate the limitation of developing a transparent reverse firewall for AKE protocols that are secure in some classical game-based models. Moreover, we prove the security of the AKE protocol of Dodis \(\text {et al.}\) in a relaxed security model with multiple users and multiple challenges.