A generic security API for symmetric key management on cryptographic devices

被引:4
|
作者
Cortier, Veronique [1 ]
Steel, Graham [2 ]
机构
[1] CNRS, Loria, UMR 7503, F-54500 Vandoeuvre Les Nancy, France
[2] INRIA Project ProSecCo, F-75013 Paris, France
基金
欧洲研究理事会;
关键词
Security APIs; Key management; PKCS#11; Cryptographic devices; AUTHENTICATION;
D O I
10.1016/j.ic.2014.07.010
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We present a new symmetric key management API for cryptographic devices intended to implement security protocols in distributed systems. Our API has a formal security policy and proofs of security in the symbolic model, under various threat scenarios. This sets it apart from previous APIs such as RSA PKCS#11, which are under-specified, lack a clear security policy and are often subject to attacks. Our design is based on the principle of explicitness: the security policy for a key must be given at creation time, and this policy is then included in any ciphertext containing the key. Our API also contains novel features such as the possibility of insisting on a freshness check before accepting an encrypted key for import. To show the applicability of our design, we give an algorithm for automatically instantiating the API commands for a given key management protocol and apply it on the Clark-Jacob protocols suite. (C) 2014 Elsevier Inc. All rights reserved.
引用
收藏
页码:208 / 232
页数:25
相关论文
共 50 条
  • [31] Modern techniques for decentralized key establishment in symmetric cryptographic systems
    Galis, Meiran
    Unkasevic, Tomislav
    Milosavljevic, Milan
    Banjac, Zoran
    Milosav, Predrag
    2021 29TH TELECOMMUNICATIONS FORUM (TELFOR), 2021,
  • [32] Symmetric and asymmetric cryptographic key exchange protocols in the octonion algebra
    Lipinski, Z.
    APPLICABLE ALGEBRA IN ENGINEERING COMMUNICATION AND COMPUTING, 2021, 32 (01) : 81 - 96
  • [33] Secured Key Distribution Scheme for Cryptographic Key Management System
    Khaing, Kyawt Kyawt
    Aung, Khin Mi Mi
    FIFTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY: ARES 2010, PROCEEDINGS, 2010, : 481 - 486
  • [34] SIKM - a smart cryptographic key management framework
    Chaeikar, Saman Shojae
    Ahmadi, Ali
    Karamizadeh, Sasan
    Chaeikar, Nakisa Shoja
    OPEN COMPUTER SCIENCE, 2022, 12 (01): : 17 - 26
  • [35] Automation System Generic Security Key Manager
    Kande, Mallikarjun
    Taylor, Nathaniel
    IECON 2018 - 44TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2018, : 2867 - 2871
  • [36] A FRAMEWORK FOR SECURE CRYPTOGRAPHIC KEY MANAGEMENT SYSTEMS
    Varalakshmi, P.
    Shajina, A. R.
    Kanimozhi, T.
    2014 SIXTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING, 2014, : 319 - 323
  • [37] Management of Symmetric Cryptographic Keys in Cloud Based Environment
    Fakhar, Faiza
    Shibli, Muhammad Awais
    2013 15TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2013, : 39 - 44
  • [38] Ensuring the security of Warfighters' SATCOM via programmable cryptographic devices
    Bull, Joseph D.
    MILCOM 2005 - 2005 IEEE MILITARY COMMUNICATIONS CONFERENCE, VOLS 1-5, 2005, : 564 - 569
  • [39] A Review of Data Security and Cryptographic Techniques in IoT based devices
    Mustafa, Ghulam
    Ashraf, Rehan
    Mirza, Muhammad Ayzed
    Jamil, Abid
    Muhammad
    ICFNDS'18: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND DISTRIBUTED SYSTEMS, 2018,
  • [40] Generic Security Services API authentication support for the Session Initiation Protocol
    Strand, Lars
    Noll, Josef
    Leister, Wolfgang
    PROCEEDINGS OF THE SEVENTH ADVANCED INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (AICT 2011), 2011, : 117 - 122