The Experts below are selected from a list of 360 Experts worldwide ranked by ideXlab platform
Ingrid Verbauwhede - One of the best experts on this subject based on the ideXlab platform.
-
a survey on lightweight Entity Authentication with strong pufs
ACM Computing Surveys, 2015Co-Authors: Jeroen Delvaux, Roel Peeters, Ingrid VerbauwhedeAbstract:Physically unclonable functions (PUFs) exploit the unavoidable manufacturing variations of an Integrated Circuit (IC). Their input-output behavior serves as a unique IC “fingerprint.” Therefore, they have been envisioned as an IC Authentication mechanism, in particular the subclass of so-called strong PUFs. The protocol proposals are typically accompanied with two PUF promises: lightweight and an increased resistance against physical attacks. In this work, we review 19 proposals in chronological order: from the original strong PUF proposal (2001) to the more complicated noise bifurcation and system of PUF proposals (2014). The assessment is aided by a unified notation and a transparent framework of PUF protocol requirements.
-
a survey on lightweight Entity Authentication with strong pufs
2015Co-Authors: Jeroen Delvaux, Roel Peeters, Ingrid VerbauwhedeAbstract:Physically unclonable functions (PUFs) exploit the unavoidable manufacturing variations of an integrated circuit (IC). Their input-output behavior serves as a unique IC ‘fingerprint’. Therefore, they have been envisioned as an IC Authentication mechanism, in particular the subclass of so-called strong PUFs. The protocol proposals are typically accompanied with two PUF promises: lightweight and an increased resistance against physical attacks. In this work, we review nineteen proposals in chronological order: from the original strong PUF proposal (2001) to the more complicated noise bifurcation and system of PUF proposals (2014). The assessment is aided by a unified notation and a transparent framework of PUF protocol requirements.
-
secure lightweight Entity Authentication with strong pufs mission impossible
Cryptographic Hardware and Embedded Systems, 2014Co-Authors: Jeroen Delvaux, Dries Schellekens, Ingrid VerbauwhedeAbstract:Physically unclonable functions PUFs exploit the unavoidable manufacturing variations of an integrated circuit IC. Their input-output behavior serves as a unique IC 'fingerprint'. Therefore, they have been envisioned as an IC Authentication mechanism, in particular for the subclass of so-called strong PUFs. The protocol proposals are typically accompanied with two PUF promises: lightweight and an increased resistance against physical attacks. In this work, we review eight prominent proposals in chronological order: from the original strong PUF proposal to the more complicated converse and slender PUF proposals. The novelty of our work is threefold. First, we employ a unified notation and framework for ease of understanding. Second, we initiate direct comparison between protocols, which has been neglected in each of the proposals. Third, we reveal numerous security and practicality issues. To such an extent, that we cannot support the use of any proposal in its current form. All proposals aim to compensate the lack of cryptographic properties of the strong PUF. However, proper compensation seems to oppose the lightweight objective.
David Pointcheval - One of the best experts on this subject based on the ideXlab platform.
-
provably authenticated group diffie hellman key exchange the dynamic case
International Conference on the Theory and Application of Cryptology and Information Security, 2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Diffie-Hellman protocols for Authenticated Key Exchange (AKE) are designed to workin a scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we define a security model for this problem and use it to precisely define Authenticated Key Exchange (AKE) with "implicit" Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then define in this model the execution of a protocol modified from a dynamic group Diffie-Hellman scheme offered in the litterature and prove its security.
-
provably authenticated group diffie hellman key exchange the dynamic case extended abstract
International Conference on the Theory and Application of Cryptology and Information Security, 2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Diffie-Hellman protocols for Authenticated Key Exchange(AKE) are designed to work in scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we define a security model for this problem and use it to precisely define Authenticated Key Exchange (AKE) with ''implicit'' Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then define in this model the execution of a protocol modified from a dynamic group Diffie-Hellman scheme offered in the literature and prove its security.
-
provably authenticated group diffie hellman key exchange the dynamic case extended abstract escholarship
2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Diffie-Hellman protocols for Authenticated Key Exchange(AKE) are designed to work in scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we define a security model for this problem and use it to precisely define Authenticated Key Exchange (AKE) with implicit Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then define in this model the execution of a protocol modified from a dynamic group Diffie-Hellman scheme offered in the literature and prove its security.
-
provably authenticated group die hellman key exchange the dynamic case full version
2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Die-Hellman protocols for Authenticated Key Exchange (AKE) are designed to work in a scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we dene a security model for this problem and use it to precisely dene Authenticated Key Exchange (AKE) with \implicit" Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then dene in this model the execution of a protocol modied from a dynamic group Die-Hellman scheme oered in the litterature and prove its security. Group Die-Hellman schemes for Authenticated Key Exchange are designed to provide a pool of players communicating over a public network and holding long-lived secrets with a session key to be used to achieve multicast message conden tiality or multicast data integrity. In this paper, we consider the scenario in which the group membership is not known in advance { dynamic rather than static { where parties may join and leave the multicast group at any given time. After the initialization phase, and throughout the lifetime of the multicast group, the parties need to be able to engage in a conversation after each change in the membership at the end of which the session key is updated to be sk 0 . The secret value sk 0 is only known to the party in the multicast group during the period when sk 0 is the session key. The adversary may generate repeated and arbitrarily ordered changes in the membership for subsets of parties of his choice. The above scenario is a distributed application in which up to one hundred parties work together in order to get a task done where many of the parties may be sending data to the multicast group (12). Examples of such applications include replicated server (21), audio-video conferencing (20) and collaborative tools (2).
Min-sung Kang - One of the best experts on this subject based on the ideXlab platform.
-
measurement device independent mutual quantum Entity Authentication
Quantum Information Processing, 2021Co-Authors: Hyung Jin Yang, Min-sung Kang, Jiwoong Choi, Chang Hoon Park, Sangwook HanAbstract:Quantum Entity Authentication (QEA) based on security guaranteed by the laws of physics is the first and most important step for secure communication under the threat of a quantum adversary. QEA theoretically provides unconditional security; however, there is a threat of quantum hacking owing to imperfection of measurement devices in the actual implementation. The proposed measurement-device-independent (MDI) mutual quantum Entity Authentication (MQEA) scheme guarantees its security under any quantum attacks on measuring devices that have been reported. Using the MDI architecture in our scheme, the third party can only know the correlation of the transmitted qubits through the Bell state measurement, and it cannot obtain the secret key information. In order to confirm the security of the proposed scheme, we present a security analysis of secret key information that is pre-shared among legitimate users, and we analyze Eve’s impersonation attack. Furthermore, we compare the MDI MQEA with other existing QEA schemes
-
response to comment on controlled mutual quantum Entity Authentication with an untrusted third party
Quantum Information Processing, 2020Co-Authors: Chang Ho Hong, Hyung Jin Yang, Sung Moon, Min-sung Kang, Jino Heo, Sangwook HanAbstract:Recently, Wang et al. (Quantum Inf Process, QINP-D-18-00478R1, 2019) commented that a third party can obtain an Authentication key from communicating parties by performing an entanglement swapping attack on the controlled mutual quantum Entity Authentication (CMQEA) protocol. In this response, we apply this attack to the CMQEA protocol and analyze whether this claim is actually valid. From the analysis, we provide a confirmation that this attack can be prevented using existing countermeasures. In addition, we propose an improved protocol that is fundamentally robust to entanglement swapping attack.
-
Controlled mutual quantum Entity Authentication with an untrusted third party
Quantum Information Processing, 2018Co-Authors: Min-sung Kang, Chang Ho Hong, Hyung Jin Yang, Sung MoonAbstract:We propose a quantum control Entity mutual Authentication protocol that can be executed in environments involving an untrusted third party. In general, the third party, referred to as Charlie, can be an Entity such as a telephone company, server, financial company, or login webpage for a portal service. Most communication protocols controlled by third parties are vulnerable to internal attacks. In this study, we present two solutions that make use of an entanglement correlation checking method and random numbers against an internal attack by an untrusted third party.
-
controlled mutual quantum Entity Authentication using entanglement swapping
Chinese Physics B, 2015Co-Authors: Chang Ho Hong, Hyung Jin Yang, Min-sung Kang, Jino Heo, Jongin LimAbstract:In this paper, we suggest a controlled mutual quantum Entity Authentication protocol by which two users mutually certify each other on a quantum network using a sequence of Greenberger–Horne–Zeilinger (GHZ)-like states. Unlike existing unidirectional quantum Entity Authentication, our protocol enables mutual quantum Entity Authentication utilizing entanglement swapping; moreover, it allows the managing trusted center (TC) or trusted third party (TTP) to effectively control the certification of two users using the nature of the GHZ-like state. We will also analyze the security of the protocol and quantum channel.
Jeroen Delvaux - One of the best experts on this subject based on the ideXlab platform.
-
a survey on lightweight Entity Authentication with strong pufs
ACM Computing Surveys, 2015Co-Authors: Jeroen Delvaux, Roel Peeters, Ingrid VerbauwhedeAbstract:Physically unclonable functions (PUFs) exploit the unavoidable manufacturing variations of an Integrated Circuit (IC). Their input-output behavior serves as a unique IC “fingerprint.” Therefore, they have been envisioned as an IC Authentication mechanism, in particular the subclass of so-called strong PUFs. The protocol proposals are typically accompanied with two PUF promises: lightweight and an increased resistance against physical attacks. In this work, we review 19 proposals in chronological order: from the original strong PUF proposal (2001) to the more complicated noise bifurcation and system of PUF proposals (2014). The assessment is aided by a unified notation and a transparent framework of PUF protocol requirements.
-
a survey on lightweight Entity Authentication with strong pufs
2015Co-Authors: Jeroen Delvaux, Roel Peeters, Ingrid VerbauwhedeAbstract:Physically unclonable functions (PUFs) exploit the unavoidable manufacturing variations of an integrated circuit (IC). Their input-output behavior serves as a unique IC ‘fingerprint’. Therefore, they have been envisioned as an IC Authentication mechanism, in particular the subclass of so-called strong PUFs. The protocol proposals are typically accompanied with two PUF promises: lightweight and an increased resistance against physical attacks. In this work, we review nineteen proposals in chronological order: from the original strong PUF proposal (2001) to the more complicated noise bifurcation and system of PUF proposals (2014). The assessment is aided by a unified notation and a transparent framework of PUF protocol requirements.
-
secure lightweight Entity Authentication with strong pufs mission impossible
Cryptographic Hardware and Embedded Systems, 2014Co-Authors: Jeroen Delvaux, Dries Schellekens, Ingrid VerbauwhedeAbstract:Physically unclonable functions PUFs exploit the unavoidable manufacturing variations of an integrated circuit IC. Their input-output behavior serves as a unique IC 'fingerprint'. Therefore, they have been envisioned as an IC Authentication mechanism, in particular for the subclass of so-called strong PUFs. The protocol proposals are typically accompanied with two PUF promises: lightweight and an increased resistance against physical attacks. In this work, we review eight prominent proposals in chronological order: from the original strong PUF proposal to the more complicated converse and slender PUF proposals. The novelty of our work is threefold. First, we employ a unified notation and framework for ease of understanding. Second, we initiate direct comparison between protocols, which has been neglected in each of the proposals. Third, we reveal numerous security and practicality issues. To such an extent, that we cannot support the use of any proposal in its current form. All proposals aim to compensate the lack of cryptographic properties of the strong PUF. However, proper compensation seems to oppose the lightweight objective.
Emmanuel Bresson - One of the best experts on this subject based on the ideXlab platform.
-
provably authenticated group diffie hellman key exchange the dynamic case
International Conference on the Theory and Application of Cryptology and Information Security, 2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Diffie-Hellman protocols for Authenticated Key Exchange (AKE) are designed to workin a scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we define a security model for this problem and use it to precisely define Authenticated Key Exchange (AKE) with "implicit" Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then define in this model the execution of a protocol modified from a dynamic group Diffie-Hellman scheme offered in the litterature and prove its security.
-
provably authenticated group diffie hellman key exchange the dynamic case extended abstract
International Conference on the Theory and Application of Cryptology and Information Security, 2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Diffie-Hellman protocols for Authenticated Key Exchange(AKE) are designed to work in scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we define a security model for this problem and use it to precisely define Authenticated Key Exchange (AKE) with ''implicit'' Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then define in this model the execution of a protocol modified from a dynamic group Diffie-Hellman scheme offered in the literature and prove its security.
-
provably authenticated group diffie hellman key exchange the dynamic case extended abstract escholarship
2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Diffie-Hellman protocols for Authenticated Key Exchange(AKE) are designed to work in scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we define a security model for this problem and use it to precisely define Authenticated Key Exchange (AKE) with implicit Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then define in this model the execution of a protocol modified from a dynamic group Diffie-Hellman scheme offered in the literature and prove its security.
-
provably authenticated group die hellman key exchange the dynamic case full version
2001Co-Authors: Emmanuel Bresson, Olivier Chevassut, David PointchevalAbstract:Dynamic group Die-Hellman protocols for Authenticated Key Exchange (AKE) are designed to work in a scenario in which the group membership is not known in advance but where parties may join and may also leave the multicast group at any given time. While several schemes have been proposed to deal with this scenario no formal treatment for this cryptographic problem has ever been suggested. In this paper, we dene a security model for this problem and use it to precisely dene Authenticated Key Exchange (AKE) with \implicit" Authentication as the fundamental goal, and the Entity-Authentication goal as well. We then dene in this model the execution of a protocol modied from a dynamic group Die-Hellman scheme oered in the litterature and prove its security. Group Die-Hellman schemes for Authenticated Key Exchange are designed to provide a pool of players communicating over a public network and holding long-lived secrets with a session key to be used to achieve multicast message conden tiality or multicast data integrity. In this paper, we consider the scenario in which the group membership is not known in advance { dynamic rather than static { where parties may join and leave the multicast group at any given time. After the initialization phase, and throughout the lifetime of the multicast group, the parties need to be able to engage in a conversation after each change in the membership at the end of which the session key is updated to be sk 0 . The secret value sk 0 is only known to the party in the multicast group during the period when sk 0 is the session key. The adversary may generate repeated and arbitrarily ordered changes in the membership for subsets of parties of his choice. The above scenario is a distributed application in which up to one hundred parties work together in order to get a task done where many of the parties may be sending data to the multicast group (12). Examples of such applications include replicated server (21), audio-video conferencing (20) and collaborative tools (2).