Subversion-Resilient Authenticated Key Exchange with Reverse Firewalls
摘要
Authenticated key exchange (AKE) protocol is an essential tool for secure communication in practice. To defend against subversion attacks that compromise the security of cryptosystem by subverting the implementation of algorithms, Dodis et al. (CRYPTO’16) introduced the first subversion-resilient AKE protocol utilizing the reverse firewalls (RFs) by Mironov and Stephens-Davidowitz (EUROCRYPT’15), and proved its security within a non-standard model. In this paper, we propose a generic subversion-resilient AKE construction under the classic game-based AKE model. Compared to Dodis \(\text {et al.}\) ’s model, our model is more strict and captures the standard multi-challenge and “single-bit-guess” security, which requires all the test keys to be real-or-random. Our AKE construction follows the standard “ \(1\times \textsf{KEM}+2\times \textsf{SIG}\) ” paradigm for designing AKE protocols, with the key encapsulation mechanism (KEM) providing some specific properties like malleability and universal decryptability. The security of our AKE construction is tightly based on the security of the underlying KEM and the underlying signature scheme. We instantiate our construction using the plain Diffie-Hellman key encapsulation, resulting in a protocol that is tightly secure based on the strong Diffie-Hellman assumption. Finally, using the strong twin Diffie-Hellman technique of Cash \(\text {et al.}\) (EUROCRYPT’08), we obtain an AKE protocol with reverse firewalls that achieves tight security based on the standard computational Diffie-Hellman assumption.