Analysis and Improvement of an Authentication Scheme in Incremental Cryptography - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Analysis and Improvement of an Authentication Scheme in Incremental Cryptography

Résumé

Introduced in cryptography by Bellare, Goldreich and Goldwasser in 1994, incrementality is an attractive feature that enables to update efficiently a cryptographic output like a ciphertext, a signature or an authentication tag after modifying the corresponding input. This property is very valuable in large scale systems where gigabytes of data are continuously processed (e.g. in cloud storage). Adding cryptographic operations on such systems can decrease dramatically their performance and incrementality is an interesting solution to have security at a reduced cost. We focus on the so-called XOR-scheme, the first incremental authentication construction proposed by Bellare, Goldreich and Goldwasser, and the only strongly incremental scheme (i.e. incremental regarding insert and delete update operations at any position in a document). Surprisingly, we found a simple attack on this construction that breaks the basic security claimed by the authors in 1994 with only one authentication query (not necessarily chosen). Our analysis gives different ways to fix the scheme; some of these patches are discussed in this paper and we provide a security proof for one of them.
Fichier principal
Vignette du fichier
main.pdf (403.38 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01893905 , version 1 (07-05-2020)

Identifiants

Citer

Louiza Khati, Damien Vergnaud. Analysis and Improvement of an Authentication Scheme in Incremental Cryptography. SAC 2018 - 25th International Conference on Selected Areas in Cryptography, Aug 2018, Calgary, Canada. pp.50-70, ⟨10.1007/978-3-030-10970-7_3⟩. ⟨hal-01893905⟩
255 Consultations
378 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More