• Aucun résultat trouvé

From Ephemerizer to Timed-Ephemerizer - Achieve Assured Lifecycle Enforcement for Sensitive Data

N/A
N/A
Protected

Academic year: 2021

Partager "From Ephemerizer to Timed-Ephemerizer - Achieve Assured Lifecycle Enforcement for Sensitive Data"

Copied!
18
0
0

Texte intégral

(1)

From Ephemerizer to

Timed-Ephemerizer: Achieve Assured Lifecycle Enforcement

for Sensitive Data

Q iang T ang

APSIA group, SnT, University of Luxembourg. 6, rue Richard Coudenhove-Kalergi, L-1359 Luxembourg

Email: [email protected]

The concept of Ephemerizer, proposed by Perlman, is a cryptographic primitive for assured data deletion. With an Ephemerizer protocol, data in persistent storage devices will always be encrypted simultaneously using an ephemeral public key of the Ephemerizer (an entity which will publish a set of ephemeral public keys and periodically delete the expired ones) and the long-term public key of a user. An Ephemerizer protocol enables the user to securely decrypt the encrypted data without leaking any information to the Ephemerizer. So far, no security model has ever been proposed for this primitive and existing protocols have not been studied formally. Not surprisingly, we show that some existing Ephemerizer protocols possess security vulnerabilities. In this paper, we review the notion of Timed-Ephemerizer, which can be regarded as a hybrid primitive by combining Ephemerizer and Timed-Release Encryption. Compared with an Ephemerizer protocol, a Timed-Ephemerizer protocol further guarantees that data will only be released after a pre-defined disclosure time. Moreover, we revisit a security model for Timed-Ephemerizer and adapt it for Ephemerizer. We also revise a previous Timed-Ephemerizer protocol by Tang and prove its security in the security model.

Keywords: Ephemerizer; storage privacy; assured lifecycle Received x; revised y

1. INTRODUCTION

Rapid growth of information technology has greatly facilitated individuals and enterprizes to generate and store sensitive data (business transaction details, electronic health records, personal profiles, etc). It is common that backups of the same piece of data will be placed on many different persistent storage devices, such as hard disks, tapes, and USB tokens.

To protect the confidentiality, sensitive data are often firstly encrypted then stored on various devices, while the cryptographic keys also need to be stored and backed up on some persistent storage devices. With respect to storing data in persistent storage devices, there are two concerns.

1. It is relatively easy to recover data from persistent storage devices, even when the data has been deleted. As such, the US government specification has suggested to overwrite non- classified information three times [1]. In contrast to persistent storage devices, it is more difficult for an adversary to corrupt volatile storage devices (for example, most forms of modern random

access memory) because the data in such devices will disappear when the electricity/power is gone.

However, it is worth noting that this could be very subtle in the presence of side channel attacks, especially when considering the cold boot attacks [2].

2. Backups of encrypted sensitive data and crypto- graphic keys often reside in many devices. Conse- quently, it is difficult to guarantee that all relevant backups have been deleted.

The above observations imply that an adversary may simultaneously obtain a copy of encrypted data and relevant cryptographic keys due to the potential management carelessness. Especially, this may be fairly easy for a malicious insider in organizations. To reduce the potential risks facing sensitive data, it is crucial to define an expiration time and strictly enforce secure deletion afterwards. Subsequently, an effective cryptographic protocol is needed for the enforcement.

Ephemerizer, proposed by Perlman [3, 4] and further studied by Nair et al. [5], has shown a promising direction towards a practical solution to the above

(2)

problem. At the core of Ephemerizer is a key management service provided by an entity, referred to as the Ephemerizer, which will publish a set of ephemeral public keys and securely delete the expired ones periodically. With an Ephemerizer protocol, data in persistent storage devices will always be encrypted simultaneously using an ephemeral public key of the Ephemerizer and the long-term public key of a user.

The novelty of asecureEphemerizer protocol is that it enables the user to securely decrypt the encrypted data without leaking any information to the Ephemerizer. If we assume that the plaintext data only reside in volatile storage devices such as memory, then an Ephemerizer protocol guarantees that expired data will remain unrecoverable even if the user’s persistent storage, the user’s long-term private key, and the unexpired private keys of the Ephemerizer have been compromised.

1.1. Problem Statement

So far, no security model has ever been proposed for Ephemerizer and existing protocols have not been analyzed formally. As a result, even if an existing Ephemerizer protocol is employed, it is not clear what kind of security guarantee will be provided.

To gain confidence in these protocols, we need to propose a formal security model and conduct corresponding security analysis. The other concern is that an Ephemerizer protocol is only supposed to provide assured deletion but not assured initial disclosure, which however could be a very useful feature in some practical applications. In a security guideline published by the Cloud Security Alliance1, thirteen domains of interest have been identified for applications in the cloud computing environment, one of which isinformation lifecycle management. As such, protocols providing assured lifecycle (marked by an assured initial disclosure and an assured deletion) will be more appealing than those providing only assured deletion. We illustrate this by an outsourcing data security example in Section 6.2.

It is worth noting that Ephemerizer and its variants only guarantee the lifecycle of data release through encryption. Once data is decrypted (e.g. residing in clear in memory), other complementary solutions are needed to securely delete the data (e.g. the state re- incarnation technique [6]). We do not consider such techniques in this work.

1.2. Our Contribution

This is an extended version of the conference paper [7], in which the author only introduced the concept of Timed-Ephemerizer and gave an instantiation. Our extentions fall into the following aspects.

Firstly, we show that some Ephemerizer protocols in [5, 3, 4] possess security vulnerabilities. Specifically,

1http://www.cloudsecurityalliance.org/

we show that the Ephemerizer protocol using blind decryption technique in [3, 4] is vulnerable to attacks from a curious Ephemerizer. More seriously, we show that the hybrid PKI-IBC Ephemerizer protocol in [5]

does not achieve assured deletion, i.e. an adversary can recover expired data.

Secondly, we provide a general overview of Timed- Ephemerizer. The workflow is illustrated in Fig.

1. Data in persistent storage devices will always be encrypted using an ephemeral public key of the Ephemerizer, the public key of the user, and the long- term public key of the time server (which will publish timestamps periodically). As a security guarantee, a Timed-Ephemerizer protocol enables the user to securely decrypt the encrypted data only during a pre- defined time slot, namely before the expiration of the ephemeral private key and the after the release of the timestamp from the time server, yet without leaking any information to the Ephemerizer or the time server.

If the time server’s private key is made public (or, the assured initial disclosure property is disabled), then Timed-Ephemerizer becomes Ephemerizer. Based on the security model for Timed-Ephemerizer, we present a security model for Ephemerizer.

FIGURE 1.An Illustration of Timed-Ephemerizer

Thirdly, we revise the Timed-Ephemerizer protocol [7] with hash function usage and prove its security in the proposed security model.

Fourthly, we compare Timed-Ephemerizer with other solutions such as Vanish [8]. As an application, we show that Timed-Ephemerizer is a useful tool for users to enforce information lifecycle management in outsourcing activities.

1.3. Organization

The rest of the paper is organized as follows. In Section 2 we briefly present some notations and

(3)

basics about pairing. In Section 3 we show that some existing Ephemerizer protocols possess security vulnerabilities. In Section 4 we review the concept of Timed-Ephemerizer and its security properties. In Section 5 we revise the Timed-Ephemerizer protocol [7]

and prove its security. In Section 6, we present some further remarks on Timed-Ephemerizer. In Section 7 we briefly review the relevant works on Ephemerizer and Timed-Release Encryption. In Section 8 we conclude the paper.

2. PRELIMINARY

Throughout the paper, we use`to denote the security parameter. The notation u ∈R S means u is chosen from the set S uniformly at random. If A is a probabilistic algorithm, then v ← A$ (f1,f2,···)(x,y,· · ·) means thatv is the result of running A, which takes x,y,· · · as input and has any polynomial number of oracle queries to the functionsf1,f2,· · ·. As a standard practice, the security of a protocol is evaluated by an experiment between an attacker and a challenger, where the challenger simulates the protocol executions and answers the attacker’s oracle queries. Without specification, algorithms are always assumed to be polynomial-time.

We now review some basics about pairing and the related assumptions. More detailed information can be found in the seminal paper [9]. A pairing (or, bilinear map) satisfies the following properties:

1. GandG1 are two multiplicative groups of prime orderp;

2. gis a generator ofG;

3. eˆ:G×G→G1is an efficiently-computable bilinear map with the following properties:

• Bilinear: for allu,v ∈ G and a,b ∈ Zp, we have ˆe(ua,vb)=e(u,ˆ v)ab.

• Non-degenerate: ˆe(g,g),1.

The Bilinear Diffie-Hellman (BDH) problem inGis as follows: given a tupleg,ga,gb,gc ∈Gas input, output e(g,ˆ g)abc ∈ G1. An algorithm A has advantage in solving BDH inGif

Pr[A(g,ga,gb,gc)=e(g,ˆ g)abc]≥.

Similarly, we say that an algorithmAhas advantage in solving the decision BDH problem inGif

|Pr[A(g,ga,gb,gc,e(g,ˆ g)abc)=0]−Pr[A(g,ga,gb,gc,T)=0]| ≥ where the probability is over the random choice of a,b,c ∈ Zp, the random choice of T ∈ G1, and the random bits ofA.

Definition 2.1.We say that the (decision) BDH assumption holds inGif no polynomial-time algorithm has a non-negligible advantage in solving the (decision) BDH problem.

Besides these computational/decisional assump- tions, the Knowledge of Exponent (KE) assumption is also used in a number of papers (e.g. [10, 11]). The KE assumption is defined as follows.

Definition2.2.For any adversaryA, which takes a KE challenge(g,ga)as input and returns(C,Y)where Y=Ca, there exists an extractorA0, which takes the same input as Areturns c such that gc =C.

3. REVIEW OF EXISTING EPHEMERIZER PRO- TOCOLS

An Ephemerizer protocol involves two types of entities:

users and an Ephemerizer. The idea behind of this primitive is quite simple. The Ephemerizer chooses a set of time timestamps, saytephj (1≤ j ≤ N) whereN is an integer, and correspondingly generates a set of ephemeral key pairs (PKteph j,SKteph j). For 1 ≤ j,k≤ N, it is assumed that if j < k then tephj < tephk (i.e.

tephk is later than tephj). Data is encrypted using a symmetric key, which will be double-encrypted using one ephemeral public key of the Ephemerizer and the public key of the user. The decryption is an interactive algorithm between the user and the Emphemerizer.

It is required that, at time tephj, the Ephemerizer will deleteSKteph j, so that any ciphertext generated under the ephemeral public keyPKteph jwill become unrecoverable afterwards.

In this section, we point out some vulnerabilities of the Ephemerizer protocol which uses the blind decryption technique in [3, 4] and the hybrid PKI-IBC Ephemerizer protocol in [5].

3.1. Ephemerizer Protocol using Blind Decryption 3.1.1. Description of the Protocol

The Ephemerizer protocol using blind de- cryption [3, 4] consists of algorithms (SetupE,SetupU,Encrypt,Decrypt), which are de- fined as follows.

• SetupE(`): The Ephemerizer generates a set of tuples

(KeyIDteph j,PKteph j,SKteph j,tephj),

where 1 ≤ j ≤ N, KeyIDteph j is the identifier of this tuple, (PKteph j,SKteph j) is a key pair of a public key encryption scheme E1 with the algorithms (Encrypt1,Decrypt1), andtephjis the expiration time of the key pair.

• SetupU(`): A user generates a key pair (PKU,SKU) for a public key encryption scheme E2 with the algorithms (Encrypt2,Decrypt2). The user also selects a symmetric key encryption scheme

E0=(Encrypt0,Decrypt0),

(4)

which has the key space K and will be used to encrypt data in the system.

• Encrypt(M,PKU,PKteph j): The ciphertext is (KeyIDteph j,C,PKteph j), whereK∈RK,

Cm=Encrypt0(M,K), Ck=Encrypt1(K,PKteph j),

Cteph j =Encrypt2(Ck,PKU), C=(Cm,Cteph j).

• Decrypt(C,SKU;SKteph j):

1. The user generates an ephemeral function pair (Blind,Unblind) satisfying the following homomorphic property:

K=Unblind(Decrypt1(Blind(Ck),SKteph j)).

2. The user then decryptsCteph j to obtainCk, and then computes and sends (KeyIDteph j,C0t

eph j) to the Ephemerizer, where

C0t

eph j = Blind(Ck).

3. If the ephemeral key SKteph j associated with KeyIDteph j has not expired, the Ephemerizer decrypts C0t

eph j and sends C00t

eph j to the user,

where C00t

eph j = Decrypt1(C0t

eph j,SKteph j)

= Decrypt1(Blind(Ck),SKteph j).

4. The user obtainsMas follows K=Unblind(C00t

eph j), M=Decrypt0(Cm,K).

With respect to the efficiency, this protocol may be quite inefficient in practice. The main reason is that the Ephemerizer potentially needs to publish and certify all the ephemeral public keys before data can be encrypted by the user. Considering the fact that the data may have a wide range of expiration time, the Ephemerizer may need to publish a large volume of key pairs.

3.1.2. Security Analysis of the Protocol

In [3, 4], the following assumptions are made on the validation of public keys.

1. The user should validate that the ephemeral public

keysPKteph j is certified by a long-term private key

of the Ephemerizer, where the corresponding long- term public key is certified by a Trusted Third Party (TTP).

2. There is no need for the Ephemerizer and the user to authenticate each other. There is no need to encrypt or protect the integrity of the ephemeral key sent to the user, i.e. there is no need for the user to check the validity ofPKteph j in any received message (KeyIDteph j,C,PKteph j).

We show below that lacking of validation ofPKteph jby the user may lead to a potential security vulnerability if the Ephemerizer is curious. As one of the options suggested in [3, 4], we suppose that the public key encryption scheme E1 is RSA [12]. Then, the above Ephemerizer protocol will be instantiated to be the following.

• SetupE(`): The Ephemerizer generates

(PKteph j,SKteph j) in the form ((ej,Nj),dj) where

ejdj≡1 (modϕ(Nj)).

• SetupU(`): The algorithm is the same as in the above.

• Encrypt(M,PKU,PKteph j): The ciphertext is (KeyIDteph j,C,(ej,Nj)), whereC=(Cm,Cteph j),

Cm=Encrypt0(M,K),

Ck=Kej modNj,Cteph j =Encrypt2(Ck,PKU).

• Decrypt(C,SKU;SKteph j):

1. The user generatesR∈RZNj

2. The user decrypts Cteph j to obtain Ck = Kej modNj, and then computes and sends (KeyIDteph j,C0t

eph j) to the Ephemerizer, where

R∈RZN, C0t

eph j =KejRej modNj. (1)

3. If the ephemeral key SKteph j associated with KeyIDteph j has not expired, the Ephemerizer decrypts C0t

eph j and sends C00t

eph j to the user,

where C00t

eph j = (C0t

eph j)dj mod Nj

= (KejRej)dj mod Nj

= KR modNj. 4. The user obtain K = C00t

eph jR1 modNj,

and then decrypts Cm to obtain M = Decrypt0(Cm,K).

Suppose the Ephemerizer has obtained (KeyIDteph j,C,(ej,Nj)) by eavesdropping on the user’s communications. In order to recover the key K, the Ephemerizer can send (KeyIDteph j,C,(ϕ(Nj),Nj)) to the user. Note that the Ephemerizer knows ϕ(Nj). Ac- cording to the Decryptalgorithm, the user will send (KeyIDteph j,C0t

eph j), where

C0t

eph j = KejRϕ(Nj) mod Nj

= Kej modNj,

(5)

to the Ephemerizer for blind decryption. Clearly, the Ephemerizer can obtainK=(C0t

eph j)dj modNj.

Due to the fact that the ephemeral public keys are only required to be certified by the private key of the Ephemerizer, the presented security vulnerability will still remain even if the user validates the public keys in the ciphertext. One possible countermeasure is to let a TTP to certify that the ephemeral public keys of Ephemerizer are generated properly.

3.2. The Hybrid PKI-IBC Ephemerizer Protocol 3.2.1. Description of the Protocol

The Ephemerizer protocol [5] consists of algorithms (SetupE,SetupU,Encrypt,Decrypt), which are defined as follows.

• SetupE(`): The Ephemerizer first generates a bilinear map ˆe:G×G→ G1, a generatorg∈RG, whereGandG1are multiplicative groups of prime orderp. The Ephemerizer then generates a long- term private key SKER Zp and the public key PKE=gSKE, two hash functions

H1:{0,1}→G, H2:G1→ {0,1}n,

and a set of ephemeral tuples

(KeyIDteph j,PKteph j,SKteph j,texpj) where 1 ≤ j ≤ N, KeyIDteph j is the identifier of this tuple, and

PKteph j = gSKtephj. Suppose also that the Ephemer-

izer possesses the identityIDE.

• SetupU(`): The user generates a key pair (PKU,SKU) for a public key encryption scheme E2with algorithms (Encrypt2,Decrypt2). The user also selects a symmetric key encryption scheme

E1 =(Encrypt1,Decrypt1),

which has the key space K and will be used to encrypt data in the system.

• Encrypt(M,PKU,PKteph j): The ciphertext is (KeyIDteph j,C), wherer∈RZp,K∈RK,

Cm=Encrypt1(M,K), Ck=Encrypt2(K,PKU), (2) IDteph j =IDE||Expiry:t0expj,

Qteph j =e(Hˆ 1(IDteph j),PKteph j),

Cteph j =(gr,Ck⊕H2((Qteph j)r)), (3)

Ct

eph j =Encrypt2(IDteph j||Cteph j,PKU), (4)

C=(Cm,Ct

eph j)

It is requiredt0expjshould be smaller thantexpjwhich is the expiration time of (PKteph j,SKteph j).

• Decrypt(C,SKU;SKteph j,SKE):

1. The user first decrypts Ct

eph j to obtain IDteph j

and Cteph j, and then computes and sends

(KeyIDteph j,ID0t

eph j,C0t

eph j) to the Ephemerizer,

where ID0t

eph jR{0,1},Q0t

eph j =e(Hˆ 1(ID0t

eph j),PKE), r0RZp, K0RK,

C0t

eph j =(gr0,(IDteph j||K0)⊕H2((Q0t

eph j)r0)). (5)

2. If the ephemeral key SKteph j associated with KeyIDteph j has not expired, the Ephemerizer decrypts C0t

eph j to obtain IDteph j and K0 as

follows

IDteph j||K0=(IDteph j||K0)⊕H2((Q0t

eph j)r0)⊕ H2(ˆe(H1(ID0t

eph j),gr0)SKE). (6)

It then computes and sendsC00t

eph j to the user,

where C00t

eph j =Encrypt1(H1(IDteph j)SKtephj,K0). (7)

3. The user decrypts C00t

eph j to obtain

H1(IDteph j)SKtephj, and then decrypts Cteph j

to obtainCkas follows.

Ck=CkH2((Qteph j)r)H2e(gr,H1(IDteph j)SKtephj)). (8)

The user then sequentially decryptsCk and Cmto obtainMas follows:

K=Decrypt2(Ck,SKU), M=Decrypt1(Cm,K). (9)

3.2.2. Security Analysis of the Protocol

On the exact expiration time. In the above protocol, when the entity, who runsEncrypt, constructsIDteph j = IDE||Expiry : t0expj, it chooses an ephemeral public key

PKteph j wheret0expj < texpj. This means that, at the time

between t0expj and texpj, if an adversary compromises both the Ephemerizer and the user, then it is able to recoverM. This observation implies that the expiration time for the ciphertextCis in facttexpjinstead oft0expj. On recovering expired data. In [5], no rigorous analysis has been done for this protocol. Next, we show that expired data can still be recovered by an adversary.

Suppose that, through eavesdropping, the adversary has obtained (C,C0t

eph j,C00t

eph j), where

C=(Cm,Ct

eph j), Cm=Encrypt1(M,K),

(6)

Ct

eph j =Encrypt2(IDteph j||Cteph j, PKU), C0t

eph j =(gr0,(IDteph j||K0)⊕H2((Q0t

eph j)r0)), C00t

eph j =Encrypt1(H1(IDteph j)SKtephj,K0).

Suppose that, at the timetephj+1, wheretephj+1 >tephj, the adversary compromises the Ephemerizer and the user, and obtainsSKEandSKU. Note that, at the timetephj+1,

SKteph j has been securely deleted and any ciphertext

encrypted withPKteph j should be unrecoverable.

1. Based on the equation (5), usingSKE, the adversary can decryptC0t

eph j and obtainIDteph j||K0.

2. Based on the equation (7), usingK0, the adversary can recoverH1(IDteph j)SKtephj by decryptingC00t

eph j. 3. Based on the equation (4), using SKU, the

adversary can recoverCteph j by decryptingC.

4. Based on the equation (3), using H1(IDteph j)SKtephj, the adversary can recoverCkby decryptingCteph j. 5. Based on the equations (2), using SKU, the

adversary can recover K by decrypting Ck, and then recoverMby decryptingCmusingK.

4. THE CONCEPT OF TIMED-EPHEMERIZER A Timed-Ephemerizer protocol guarantees that encrypted data will only be recoverable during a pre-defined lifecycle, beyond which no adversary can recover the data even if it has compromised all existing private keys in the system. Compared with Ephemerizer protocols [5, 3, 4], a Timed-Ephemerizer protocol explicitly provides the guarantee that data can only be available after the pre-defined initial disclosure time.

Generally, a Timed-Ephemerizer protocol involves the following types of entities: a time server, users, and an Ephemerizer. Compared with an Ephemerizer protocol, a Timed-Ephemerizer protocol has one additional entity, namely the time server. One may have the observation that the Ephemerizer can be required to release timestamps so that the time server can be eliminated. However, we argue that the separation of functionalities provides a higher level of security guarantee in general. First of all, the time server only needs to publish timestamps without any additional interaction with other entities. In practice, the risk that time server is compromised is less than that for the Ephemerizer. Secondly, the risk that both the Ephemerizer and the time server are compromised is less than that one of them is compromised.

The idea behind of this new primitive is similar to that of Ephemerizer. The Ephemerizer plays the same role as in the case of Ephemerizer and generates a set of ephemeral key pairs (PKteph j,SKteph j) (1 ≤ j ≤ N).

The time server defines a time setT and sequentially

publishes a timestamp TSt at the time t ∈ T. Data is encrypted using a symmetric key, which will be encrypted using one ephemeral public key of the Ephemerizer and the public key of the user while taking into account an initial disclosure time tint ∈ T. The decryption is an interactive algorithm between the user and the Emphemerizer. The security is mainly based on two facts.

1. Only at time t ∈ T, the time server publishes a timestamp TSt, so that any ciphertext generated with timetwill only become recoverable aftert.

2. At the time tephj, the Ephemerizer will delete

SKteph j, so that any ciphertext generated under

the ephemeral public key PKteph j will become unrecoverable afterwards.

In the rest of this section, we define the algorithms of Timed-Ephemerizer and formalize its security properties.

4.1. The Algorithm Definitions

A Timed-Ephemerizer protocol consists of the following algorithms. Note that, compared with an Ephemerizer protocol, there are two additional algorithms, namelySetupT andTimeExt.

• SetupT(`): Run by the time server, this algorithm generates a public/private key pair (PKT,SKT). In addition, the time server also publishes a time set T.

• TimeExt(t,SKT): Run by the time server, this algorithm generates a timestamp TSt for t ∈ T. It is assumed that the time server publishesTStat the pointt.

• SetupE(`): Run by the Ephemerizer, this algorithm generates a set of tuples (PKteph j,SKteph j,tephj), where 1 ≤ j ≤ N, (PKteph j,SKteph j) is an ephemeral public/private key pair, andtephj is the expiration time. The Ephemerizer will securely deleteSKteph j

at the pointtephj. We assume that there is only one ephemeral key pair for any expiration timetephj.

• SetupU(`): Run by a user, this algorithm generates a public/private key pair (PKU,SKU).

• Encrypt(M,tint,PKU,PKteph j,PKT): This algorithm outputs a ciphertext C. For the message M, tint∈ T is the initial disclosure time andtephjis the expiration time. We explicitly assume that both (tint,tephj) andCshould be sent to the user.

• Decrypt(C,TStint,SKU;SKteph j): Run between the user and the Ephemerizer, this algorithm outputs a plaintextMor an error symbol for the user.

In the algorithm definitions, besides the explicitly specified parameters, other public parameters could

(7)

also be specified and be implicitly part of the input. We omit those parameters for the simplicity of description.

In the algorithm designs, we let the time server and the Ephemerizer choose T and tephj (1 ≤ j ≤ N) respectively. How to choose these timestamps is a practical issue, and may be subject to the application environment where a Timed-Ephemerizer protocol will be used. However, no matter how this will be done, it will not affect our security analysis.

Note that a Timed-Ephemerizer protocol can be employed by an entity, say Alice, to protect her own data in persistent storage devices or protect her data that she wants to share with another entity, say Bob. In the first situation, Alice encrypts her data Encrypt(M,tint,PKA,PKteph j,PKT), wherePKA is Alice’s public key. In the second situation, Alice encrypts her dataEncrypt(M,tint,PKB,PKteph j,PKT), wherePKBis Bob’s public key. The example in Section 6.2 is in the second situation.

Similar to other cryptographic primitives, the basic requirement to Timed-Ephemerizer is soundness.

Informally, this property means that the algorithms EncryptandDecryptwork properly with valid inputs.

Formally, it is defined as follows.

Definition4.1.A Timed-Ephemerizer protocol achieves (unconditional) soundness if the following equality always holds for any M,tint,j.

Decrypt(Encrypt(M,tint,PKU,PKteph j,PKT),TStint,SKU;SKteph j)=M.

4.2. The Security Definitions

With respect to the entities involved in a Timed- Ephemerizer protocol, we make the following trust assumptions.

• The time server publishesTStat the timet, where t ∈ T. Except for this, the time server may try to obtain some information about users’ plaintext data.

• A user is supposed to access the data during its lifecycle, but not beyond it. Furthermore, the user will not store plaintext data on persistent storage devices.

• The Ephemerizer publishes ephemeral pub- lic/private key pairs and revoke them periodically.

Except for this, the time server may try to obtain some information about users’ plaintext data.

A Timed-Ephemerizer protocol is aimed to guarantee that data will only be available during its lifecycle, while neither before the initial disclosure time nor after the expiration time. We assume that the validation of public keys in the protocol can be verified by all the participants. For example, the validation can be done with the help of a TTP. Note that the validation of keys are crucial to achieve the security properties against both Type-I and Type-II

adversaries. We generally assume that an outside adversary is active, which means that the adversary may compromise the protocol participants and fully control the communication channels (i.e. capable of deleting, relaying, and replacing the messages exchanged between the participants). Considering the threats against confidentiality of data, we identify three categories of adversaries.

• Type-I adversary: This type of adversary wants to access data before its initial disclosure time. Type- I adversary represents a curious user and also a malicious outside entity which has compromised the Ephemerizer and the user before the initial disclosure time of the data.

• Type-II adversary: This type of adversary wants to access data after its expiration time. Type-II adversary represents a malicious outside entity which has compromised the time server, the Ephemerizer, and the user after the expiration time of the data.

• Type-III adversary: This type of adversary represents a malicious time server and a malicious Ephemerizer, and also a malicious outside entity which has compromised the time server and the Ephemerizer.

The implications of a Type-I adversary and a Type-II adversary are clear for a Timed-Ephemerizer protocol.

Nonetheless, the existence of a Type-III adversary still makes sense even in the presence of these two types of adversary. Compared with a Type-I adversary, a Type-III adversary has the advantage of accessing the private key (and all timestamps) of the time server;

while compared with a Type-II adversary, a Type- III adversary has the advantage of accessing all the private keys of the Ephemerizer. However, a Type- III adversary does not have direct access to the user’s private key.

It is worth stressing that when the adversary com- promises an entity (the time server, the Ephemerizer, or the user) it will obtain the private keys possessed by that entity. For example, if the Ephemerizer is compro- mised at the pointt, then it will obtain all the private

keysSKteph j fortephj >t. However, we do not take into

account the compromise of ephemeral session secrets during the executions of algorithms.

Definition4.2.A Timed-Ephemerizer protocol achieves Type-I semantic security if any polynomial-time adversary has only a negligible advantage in the following semantic security game (as shown in Fig. 2), where the advantage is defined to be|Pr[b0=b]−1

2|.

In the attack game, PK means all available public keys. In more detail, the attack game between the challenger and the adversaryAperforms as follows.

In this game the challenger simulates the functionality of the time server.

(8)

1. (PKT,SKT)←$ SetupT(`);

(PKteph j,SKteph j) for 1≤j≤ N ←$ SetupE(`);

(PKU,SKU)←$ SetupU(`) 2. (M0,M1,tint,PKt

ephi)←A$ (TimeExt)(SKt

eph j (1 ≤ j ≤

N),SKU,PK)

3. b← {$ 0,1};Cb$ Encrypt(Mb,tint,PKU,PKtephi,PKT) 4. b0←A$ (TimeExt)(Cb,SKteph j for 1≤j≤ N,SKU,PK) FIGURE 2.Semantic Security against Type-I Adversary

1. The challenger runsSetupTto generate (PKT,SKT), runs SetupE to generate (PKteph j,SKteph j) for 1 ≤ j ≤ N, and runs SetupU to generate (PKU,SKU).

Except for SKT, all private keys and all public parameters are given to the adversary.

2. The adversary can adaptively query theTimeExt oracle, for which the adversary provides a time t and gets a timestamp TSt from the challenger.

At some point, the adversary sends the challenger two equal-length plaintext M0,M1 on which it wishes to be challenged, and two timestamps (tint,tephi) wheretint ∈ T and 1 ≤i ≤ N. The only restriction is that theTimeExt oracle should not have been queried witht≥tint.

3. The challenger picks a random bitb ∈ {0,1}and gives the adversaryCbas the challenge, where

Cb=Encrypt(Mb,tint,PKU,PKtephi,PKT).

4. The adversary can continue to query theTimeExt oracle with the same restriction as in Step 2.

5. Eventually, the adversary outputsb0.

In the above attack game, the adversary is Type- I because it has access to SKU and SKteph j for any 1 ≤ j ≤ N. The restriction in steps 2 and 4 of the above game, namely “the TimeExtoracle should not have been queried with t ≥ tint.”, implies that the adversary tries to recover a message before the initial disclosure time. This coincides with the definition of Type-I adversary.

Definition4.3.A Timed-Ephemerizer protocol achieves Type-II semantic security if any polynomial-time adversary has only a negligible advantage in the following semantic security game (as shown in Fig. 3), where the advantage is defined to be|Pr[b0=b]−1

2|.

In the attack game, PK means all available public keys. In more detail, the attack game between the challenger and the adversaryAperforms as follows. In this game the challenger simulates the functionalities of both the Ephemerizer and the user.

1. The challenger runsSetupTto generate (PKT,SKT), runs SetupE to generate (PKteph j,SKteph j) for 1 ≤

1. (PKT,SKT)←$ SetupT(`); (PKteph j,SKt

eph j) for 1≤j≤

N←$ SetupE(`); (PKU,SKU)←$ SetupU(`)

2. (M0,M1,tint,PKtephi)←A$ (Decrypt)(SKT,SKteph j for 1 ≤ j≤ N,SKU,PK)

3. b← {$ 0,1};Cb$ Encrypt(Mb,tint,PKU,PKtephi,PKT) 4. b0←A$ (Decrypt)(Cb,SKT,SKt

eph j for i < j ≤

N,SKU,PK)

FIGURE 3.Semantic Security against Type-II Adversary

j ≤ N, and runs SetupU to generate (PKU,SKU).

The private keySKTand all public parameters are given to the adversary.

2. The adversary can adaptively issue the following two types ofDecryptoracle queries.

(a) D-type Decrypt oracle query: In each oracle query, the adversary impersonates the Ephemerizer and provides (tint,tephj) andCto the challenger, which then uses (C,TStint,SKU) as input and runs the Decrypt algorithm with the adversary to decryptCby assuming that the initial disclosure time istint and the expiration time istephj.

(b) E-typeDecryptquery: In each oracle query, the adversary impersonates a user to the Ephemerizer and sendstephjto the challenger, which uses SKteph j as the input and runs the Decryptalgorithm with the adversary.

At some point, the adversary sends the challenger two equal-length plaintext M0,M1 on which it wishes to be challenged, and two timestamps (tint,tephi) where tint ∈ T and 1 ≤ i ≤ N. In this phase, the adversary can query forSKUandSKteph j

for anyi < j ≤ N with the following restriction:

ifSKUhas been queried, then anyE-typeDecrypt oracle query with the inputtephjfor any 1≤j≤iis forbidden.

3. The challenger picks a random bit b ∈ {0,1} and gives the adversaryCbas the challenge, where

Cb=Encrypt(Mb,tint,PKU,PKtephi,PKT).

4. The adversary can continue to issue oracle queries as in Step 2 with the same restriction.

5. The adversaryAoutputsb0.

In the above attack game, the adversary is Type- II because it has access to the private keys SKT, SKU, and SKteph j for any i < j ≤ N. In the above game, the privilege, that the adversary can issue the two types of Decrypt oracle queries, reflects the fact that the adversary has complete control over the communication link between the user and the Ephemerizer. In practice, such an adversary can initiate

(9)

theDecryptalgorithm with both the Ephemerizer and the user. The first case is modeled by theE-typeDecrypt query, while the second case is modeled by the D- typeDecryptquery. The restriction in the above game, namely “ifSKUhas been queried, thenE-typeDecrypt oracle query with the input tephj for any 1 ≤ j ≤ i is forbidden.”, reflects the fact that the adversary tries to recover a message after its expiration timetephi (when the ephemeral keys SKteph j for any 1 ≤ j ≤ i should have been securely deleted by the Ephemerizer). This coincides with the definition of Type-II adversary.

Definition4.4.A Timed-Ephemerizer protocol achieves Type-III semantic security if any polynomial-time adversary has only a negligible advantage in the following semantic security game (as shown in Fig. 4), where the advantage is defined to be|Pr[b0=b]−1

2|.

1. (PKT,SKT)← A$ (`); (PKteph j,SKt

eph j)for1≤j≤ N←$

A(`); (PKU,SKU)←$ SetupU(`)

2. (M0,M1,tint,PKtephi)←A$ (Decrypt)(SKT,SKteph j for 1≤ j≤ N,PK)

3. b← {$ 0,1};Cb$ Encrypt(Mb,tint,PKU,PKtephi,PKT) 4. b0←A$ (Decrypt)(Cb,SKT,SKt

eph jfor 1≤j≤ N,PK)

FIGURE 4.Semantic Security against Type-III Adversary

In the attack game, PK means all available public keys. In more detail, the attack game between the challenger and the adversary Aperforms as the following. In this game the challenger simulates the functionality of the user.

1. The adversary A generates (PKT,SKT) and

(PKteph j,SKteph j) for 1 ≤ j ≤ N. Note that

the adversary may not follow the protocol specification to generate these parameters. The challenger runs SetupU to generate (PKU,SKU).

The public keyPKUis given to the adversary.

2. The adversary can adaptively issue the D-type Decryptoracle query (defined as above). At some point, the adversary sends the challenger two equal-length plaintextM0,M1 on which it wishes to be challenged, and two timestamps (tint,tephi) wheretint∈ T and 1≤i≤ N.

3. The challenger picks a random bitb ∈ {0,1}and gives the adversaryCbas the challenge, where

Cb=Encrypt(Mb,tint,PKU,PKtephi,PKT).

4. The adversary can continue to query theDecrypt oracle as in Step 2.

5. The adversaryAoutputsb0.

In the above attack game, the adversary is Type-III because it has access to the private keysSKTandSKteph j

for any 1 ≤ j≤ N. In the above game, expect for the

user’s private key, the adversary is allowed to access all other secrets. In particular, this means that an outside adversary can compromise both the time server and the Ephemerizer at any time. This coincides with the definition of Type-III adversary.

5. A NEW TIMED-EPHEMERIZER PROTOCOL In this section, we propose revise the Timed- Ephemerizer protocol from [7] and prove its security.

The philosophy behind the proposed protocol is similar to the blind decryption technique [3, 4]. As in the case of the hybrid PKI-IBC protocol [5], the proposed protocol also adopts the concept of identity-based encryption [9, 13] to avoid publishing a large volume of ephemeral public keys. Here are some intuitions about the construction.

1. Encryption.Data is first encrypted jointly using the ephemeral public key of the Ephemerizer and the public key of the time server. This is illustrated in the generation of the elementC4in the ciphertext, referring to the equation (10). The ciphertext is then re-encrypted using the public key of the user. The ⊕ operation in generating C4 allows the re-randomization in the decryption, while the checksumC7 is important to achieve the security properties against Type-I and Type-II adversaries (technically, allowing us to answer the adversaries’

oracle queries in the proofs).

2. Decryption. In order to achieve the security property against Type-III adversary, the ciphertext need to be re-randomized in the decryption algorithm. As a result, in decryption, the ciphertext is firstly decrypted using the user’s private key, and then re-randomized using a random number. This is illustrated in the generation of the element C04 in the ciphertext, referring to the equation (12). The re-randomized data is then encrypted using an ephemeral public key of the Ephemerizer and sent to the the Ephemerizer. This additional encryption process is used to prevent replay attacks from Type-I and Type-II adversaries, due to the fact that the re- randomization is simply an XOR operation.

5.1. The Proposed Construction

Let {0,1}n be the message space of user, wheren is a polynomial in`. The polynomial-time algorithms are defined as follows.

• SetupT(`): This algorithm generates the following parameters: a multiplicative group G of prime order p, a generator g ofG, and a multiplicative group G1 of the same order asG, a polynomial- time computable bilinear map ˆe :G×G →G1, a cryptographic hash functionH1, and a long-term

(10)

public/private key pair (PKT,SKT) where H1:{0,1}→G,SKTRZp, PKT =gSKT. The time server also publishes (G,G1,p,g,e,ˆH1).

Suppose that the time server possesses the identity IDT. In addition, the time server also publishes a time setT. Since the details how to defineT will not affect out analysis, we keep it at an abstract level.

• TimeExt(t,SKT): This algorithm returns TSt = H1(IDT||t)SKT.

• SetupE(`): Suppose that the Ephemerizer possesses the identityIDE. The Ephemerizer uses the same set of parameter (G,G1,p,g,e) as by theˆ time server and selects the supported expiration times tephj (1 ≤ j ≤ N) where N is an integer.

The Ephemerizer generates a master key pair (PK(0)E ,SK(0)E ) and a hash functionH2, where

SK(0)ERZp,PKE(0)=gSKE(0), H2:{0,1}→ {0,1}n, and sets, for 1≤ j≤ N,

PK(0)t

eph j =IDE||tephj, SK(0)t

eph j =H1(IDE||tephj)SK(0)E. The Ephemerizer generates another master key pair (PK(1)E ,SKE(1)) for an identity-based public key encryption scheme E1 with the encryp- tion/decryption algorithms (Encrypt1,Decrypt1), and, for 1 ≤ j ≤ N, generates the ephemeral key pairs

(PK(1)t

eph j,SKt(1)

eph j), wherePKt(1)

eph j =IDE||tephj. Suppose the message space and ciphertext space of the encryption scheme E1 are Y and W, respectively. The Ephemerizer keeps a set of tuples

(PKteph j,SKteph j,tephj) for 1≤ j≤ N, where

PKteph j =(PKt(0)

eph j,PK(1)t

eph j),SKteph j =(SK(0)t

eph j,SKt(1)

eph j) In addition, the Ephemerizer deletes SK(0)E ,SKE(1) and publishes the long-term public keys PK(0)E ,PKE(1).

• SetupU(`): This algorithm generates a pub- lic/private key pair (PKU,SKU) for a public key encryption scheme E2 with the encryp- tion/decryption algorithms (Encrypt2,Decrypt2).

Suppose the message space ofE2 isXand the ci- phertext space isD. The user publishes the fol- lowing hash functions.

H3:G×G→G,H4:Y →G×G×G× {0,1}n, H5:X →G×G×G× {0,1}n.

• Encrypt(M,tint,PKU,PKteph j,PKT): This algorithm outputs a ciphertextC, where

r1,r2RZp,X∈RX,C1=gr1,C2=gr2,C3=H3(C1||C2)r1,

C4 = MH2e(H1(PK(0)

tephj

),PK(0)E)r1·e(Hˆ 1(IDT||tint),PKT)r2) (10)

= MH2e(H1(IDE||teph j),C1)SK(0)E ·ˆe(H1(IDT||tint),C2)SKT)(11)

C5=Encrypt2(X,PKU),C6=H5(X)⊕(C1||C2||C3||C4), C7=H2(X||C1||C2||C3||C4||C5||C6), C=(C5,C6,C7).

• Decrypt(C,TStint,SKU;SKteph j):

1. The user decryptsC5to obtainX, and aborts if the following inequality is true.

C7,H2(X||(C6⊕H5(X))||C5||C6) Otherwise it computes C1||C2||C3||C4 = H5(X)⊕C6. The user then retrievesTStintfrom the time server and checks that ˆe(TStint,g) = ˆ

e(H1(IDT||tint),PKT). If so, it computes and sends (C0,TStint) to the Ephemerizer, where M0R{0,1}n,

C01=C1,C02=C2,C30 =C3,C04=M0⊕C4, (12) Y∈RY,C05=Encrypt1(Y,PKt(1)

eph j), C06=H4(Y)⊕(C01||C02||C03||C04), C07=H2(Y||C01||C02||C03||C04||C05||C06),

C0=(C05,C06,C07).

2. If the ephemeral key SKteph j = (SK(0)t

eph j,SK(1)t

eph j) has not expired, the Ephemerizer decryptsC05 to obtainY, and aborts if

C07,H2(Y||(C06⊕H4(Y))||C05||C06).

It then computesC01||C02||C03||C04 = H4(Y)⊕C06, and aborts if

ˆ

e(C03,g),e(Cˆ 01,H3(C01||C02)) Finally, it sendsC00 to the user, where

C00 = H2(Y||C10||C02||C03||C04)C04H2e(C01,SK(0)

tephj

)·e(TSˆ tint,C02))

= H2(Y||C01||C02||C03||C04)M0M.

3. The user recoversM= H2(Y||C01||C02||C03||C04)⊕ M0⊕C00.

Since identity-based encryption is used, only the long-term public key PKE = (PK(0)E ,PKE(1)) needs to be certified by a TTP. Instead of publishing and certifying all the ephemeral public keys, as in the case of [3, 4], the Ephemerizer only needs to publish tephj

Références

Documents relatifs

Using U-Pb dating of detrital sediments and volcanics, Schaltegger (1997c) revealed the great similarity of Pennsylvanian– Permian sediments from boreholes located at the limits

This way, Puri reduced the problem of finding the set S ∗ to the problem of finding all reachable strongly connected components on the region graph of a timed automaton and

From the software implementation in C, we derive the specifications of an abstract proto- col for public key distribution, encryption and trust establishment; then, we model

Si nous étudions indépendamment la gêne perçue pour chaque situation sonore, nous pouvons noter que les bruits de type impulsionnel bien que leur intensité soit faible, comme

As shown in Figure 2 , we observed a significant correlation of either high RIP140 (p = 0.003), high LCoR (p = 0.028), or high ERβ (p = 0.001) expression with poor OS in the

The research challenges we are tackling are related to the population of this rich ontological model from raw library metadata and on its visualization that should enable users

The ‘refugee camp’ class mapping was mainly based on settlement locations classified as ‘IDP camp’: (i) information on population sizes were used to pro- vide an estimate of IDP

The significantly positive effects identified in the short and/or medium term for South Africa and The Gambia imply that SARAs have generated significant revenue gains in