- Supplementary Content
- 10.25534/tuprints-00014550
Cryptographic Primitives that Resist Backdooring and Subversion
- Apr 04, 2021
- TUbilio (Technical University of Darmstadt)
- Sogol Mazaheri
Cryptographic Primitives that Resist Backdooring and Subversion
New communications paradigms such as wireless communications for handheld devices have increased requirements for operating speed of relevant security mechanisms, such as encryption for confidentiality, hashing for message integrity and combined hashing and public key encryption for digital signature. Existing secure services have traditionally been implemented by employing hybrid cryptographic protocols, i.e. combinations of symmetric and asymmetric (public key) algorithms to handle both effective key management and cryptographic performance. These solutions are in increasing degree becoming obsolete by the trend to connect end users with terminals with limited storage and processing power via wireless networks, sometimes established in a totally ad hoc fashion, with little or no centralized management to organize user authorization for access to secured services. New, lightweight protocols are in increasing demand, and the cryptographic primitives necessary for implementation of such protocols also need to be adapted to these new user scenarios.At NTNU/Q2S, research in this area has been ongoing for a period of time resulting in a number of new solutions adapted to the new paradigm encompassing mobile users of distributed communication services. In this talk, some of the general features of the new cryptographic primitives will be described. The designs are mainly based on new insight into the characteristics of quasigroups and quasi group string operations.
Cryptographic Primitives that Resist Backdooring and Subversion
Cryptographic Primitives that Resist Backdooring and Subversion
Bringing Theory Closer to Practice in Post-quantum and Leakage-resilient Cryptography
Modern cryptography pushed forward the need of having provable security. Whereas ancient cryptography was only relying on heuristic assumptions and the secrecy of the designs, nowadays researchers try to make the security of schemes to rely on mathematical problems which are believed hard to solve. When doing these proofs, the capabilities of potential adversaries are modeled formally. For instance, the black-box model assumes that an adversary does not learn anything from the inner-state of a construction. While this assumption makes sense in some practical scenarios, it was shown that one can sometimes learn some information by other means, e.g., by timing how long the computation take. In this thesis, we focus on two different areas of cryptography. In both parts, we take first a theoretical point of view to obtain a result. We try then to adapt our results so that they are easily usable for implementers and for researchers working in practical cryptography. In the first part of this thesis, we take a look at post-quantum cryptography, i.e., at cryptographic primitives that are believed secure even in the case (reasonably big) quantum computers are built. We introduce HELEN, a new public-key cryptosystem based on the hardness of the learning from parity with noise problem (LPN). To make our results more concrete, we suggest some practical instances which make the system easily implementable. As stated above, the design of cryptographic primitives usually relies on some well-studied hard problems. However, to suggest concrete parameters for these primitives, one needs to know the precise complexity of algorithms solving the underlying hard problem. In this thesis, we focus on two recent hard-problems that became very popular in post-quantum cryptography: the learning with error (LWE) and the learning with rounding problem (LWR). We introduce a new algorithm that solves both problems and provide a careful complexity analysis so that these problems can be used to construct practical cryptographic primitives. In the second part, we look at leakage-resilient cryptography which studies adversaries able to get some side-channel information from a cryptographic primitive. In the past, two main disjoint models were considered. The first one, the threshold probing model, assumes that the adversary can put a limited number of probes in a circuit. He then learns all the values going through these probes. This model was used mostly by theoreticians as it allows very elegant and convenient proofs. The second model, the noisy-leakage model, assumes that every component of the circuit leaks but that the observed signal is noisy. Typically, some Gaussian noise is added to it. According to experiments, this model depicts closely the real behaviour of circuits. Hence, this model is cherished by the practical cryptographic community. In this thesis, we show that making a proof in the first model implies a proof in the second model which unifies the two models and reconciles both communities. We then look at this result with a more practical point-of-view. We show how it can help in the process of evaluating the security of a chip based solely on the more standard mutual information metric.
Read moreEnergy-efficient mechanisms in security of the internet of things: A survey
Energy-efficient mechanisms in security of the internet of things: A survey
Feasibility characterization of cryptographic primitives for constrained (wearable) IoT devices
The Internet of Things (IoT) employs smart devices as its building blocks for developing a ubiquitous communication framework. It thus supports a wide variety of application domains, including public safety, healthcare, education, and public transportation. While offering a novel communication paradigm, IoT finds its requirements closely connected to the security issues. The role of security following the fact that a new type of devices known as wearables constitute an emerging area. This paper delivers an applicability study of the state-of-the-art cryptographic primitives for wearable IoT devices, including the pairing-based cryptography. Pairing-based schemes are well-recognized as fundamental enablers for many advanced cryptographic applications, such as privacy protection and identity-based encryption. To deliver a comprehensive view on the computational power of modern wearable devices (smart phones, watches, and embedded devices), we perform an evaluation of a variety of them utilizing bilinear pairing for real-time communication. In order to deliver a complete picture, the obtained bilinear pairing results are complemented with performance figures for classical cryptography (such as block ciphers, digital signatures, and hash functions). Our findings show that wearable devices of today have the needed potential to efficiently operate with cryptographic primitives in real time. Therefore, we believe that the data provided during this research would shed light on what devices are more suitable for certain cryptographic operations.
Read moreSOHCL-RDT: A self-organized hybrid cross-layer design for reliable data transmission in wireless network
SOHCL-RDT: A self-organized hybrid cross-layer design for reliable data transmission in wireless network
The comparisons between public key and symmetric key cryptography in protecting storage systems
As public key cryptographic operations are computationally expensive; it motivates a careful examination of the reasons of its usage and looking for symmetric key alternatives. In this paper, we present comparisons between public key and symmetric key cryptography in protecting storage and take some other factors, such as security, cost and environment etc. into consideration. At first, the comparisons between public key and symmetric key cryptography is presented. Then, the security services that some famous storage systems provide and some symmetric key alternatives are discussed. We give the comparisons of some practice storage systems and trade off some other parameters. Finally, some general conclusions are made about the secure storage systems for system designers.
Read moreEnergy Efficiency in Wireless Sensor Networks: Selected Papers from IEEE PIMRC 2008
Wireless Sensor Networks (WSNs) have emerged as perhaps the most important networking paradigm of recent times, both in terms of their commercial potential and also from a scientific point of view. WSNs are important commercially because of their many applications, spanning from civil to military applications such as structural monitoring of bridges, monitoring of wildlife, tracking of contaminants in the soil and atmosphere. Some of these applications have already proved to be commercially viable and indeed financially very attractive. WSNs are also very important from a scientific point of view, because of their unique features with respect to other types of wireless networks: nodes are typically immobile, and are required to carry a specific type of traffic (which is advantageous), have extreme restrictions on the energy they consume, the processing power they have, and the antennas they can use (which is disadvantageous); in addition, the data created at different sensors may be strongly correlated, which can be beneficial but requires only good algorithms that take advantage of it. Therefore, in the last few years we have experienced an important shift in research activities, moving from general purpose wireless networks to more focused topics specifically on WSNs, taking into account their specific advantages and peculiarities. An important recurring theme in research in this field is the need for energy efficiency, which is the thread of this special issue. The papers which appear in this issue have been carefully selected from the best IEEE PIMRC 2008 conference papers addressing the issue of energy efficiency in WSNs. The respective authors have been asked to provide a significantly extended version of the conference paper, which has subsequently undergone a rigorous review process according to the IJWIN publication standards prior to acceptance. The final set of papers addresses issues at physical, medium access control and networking layers, and to some extent at the application layer. All of these papers take into account the unique peculiarities, advantages, and shortcomings of wireless sensor networks, and propose algorithms and analyses that significantly advance research in the field. We sincerely hope you will enjoy reading them as much as we did. The author of the first paper ‘‘Power Management and Data Rate Maximization in Wireless Energy Harvesting Sensors’’ by Chandra R. Murthy, deals with the problem of power management and throughput maximization for energy neutral operation when using increasingly important but so far rarely analyzed Energy Harvesting Sensors (EHS) to send data over wireless links. The EHS is assumed to be able to harvest energy at a constant rate, and use a fixed part of the energy harvested in a slot for measuring the channel state. The rest of the harvested energy is available for transmission, but it can also be stored in an Wireless Sensor Networks (WSNs) have emerged as perhaps the most important networking paradigm of recent times, both in terms of their commercial potential and also from a scientific point of view. The papers that appear in this issue have been carefully selected from the best IEEE PIMRC 2008 conference papers which addressed the issue of energy efficiency in WSNs. The final set of papers addresses issues at physical, medium access control, networking and to some extend application layers. All of these papers take into account the unique peculiarities, advantages, and shortcomings of wireless sensor networks, and propose algorithms and analyses that significantly advance research in the field. Note that this activity has been partly supported by the NoE-216715 NEWCOM++.
Read moreProvably Secure and Lightweight Patient Monitoring Protocol for Wireless Body Area Network in IoHT
As one of the important applications of Internet of Health Things (IoHT) technology in the field of healthcare, wireless body area network (WBAN) has been widely used in medical therapy, and it can not only monitor and record physiological information but also transmit the data collected by sensor devices to the server in time. However, due to the unreliability and vulnerability of wireless network communication, as well as the limited storage and computing resources of sensor nodes in WBAN, a lot of authentication protocols for WBAN have been devised. In 2021, Alzahrani et al. designed an anonymous medical monitoring protocol, which uses lightweight cryptographic primitives for WBAN. However, we find that their protocol is defenseless to off-line identity guessing attacks, known-key attacks, and stolen-verifier attacks and has no perfect forward secrecy. Therefore, a patient monitoring protocol for WBAN in IoHT is proposed. We use security proof under the random oracle model (ROM) and automatic verification tool ProVerif to demonstrate that our protocol is secure. According to comparisons with related protocols, our protocol can achieve both high computational efficiency and security.
Read moreAn Efficient Elliptic Curves Scalar Multiplication for Wireless Network
Mobile and wireless devices like cell phones and network enhanced PDAs have become increasingly popular in recent years. The security of data transmitted via these devices has become the bottleneck for wireless network. Elliptic curves cryptography (ECC) is especially attractive for devices and is suited for wireless network, which has restrictions of the limited bandwidth, processing power, storage space and power consumption. The efficiency of ECC implementation is highly dependent on the performance of arithmetic operations of scalar multiplication(SM) dP, which mainly applied in encryption, signature and protocol. A new signed binary representation (SBR) for integers is proposed, which needs less memory and cost of computation compared to other methods mentioned in this paper. According to analyzing and comparing to other methods, algorithm for computing dP using new SBR is more efficient in window methods and is the simplest for applying in software and hardware. The new SBR needs less computational power and memory and can improve the security of wireless network efficiently.
Read moreLess is More
Concurrent transmissions, a novel communication paradigm, has been shown to effectively accomplish a reliable and energy-efficient flooding in wireless networks. With multiple nodes exploiting a receive-and-forward scheme in the network, this technique inevitably introduces communication redundancy and consequently raises the energy consumption of the nodes. In this paper, we propose LiM, an energy-efficient flooding protocol for wireless sensor networks. LiM builds on concurrent transmissions, exploiting constructive interference and the capture effect to achieve high reliability and low latency. Moreover, LiM equips itself with a machine learning capability to progressively reduce redundancy while maintaining high reliability. As a result, LiM is able to significantly reduce the radio-on time and therefore the energy consumption. We compare LiM with our baseline protocol Glossy by extensive experiments in the 30-node testbed FlockLab. Experimental results show that LiM highly reduces the broadcast redundancy in flooding. It outperforms the baseline protocol in terms of radio-on time, while attaining a high reliability of over 99.50%, and an average end-to-end latency around 2 ms in all experimental scenarios.
Read moreTCP-MAC Interaction in Multi-hop Ad-hoc Networks
Recent demands on affordable, portable wireless communication and computation devices have resulted in exponential growth of wireless networks ranging from Wireless Local Area Networks (WLAN) and Wireless Wide Area Networks (WWAN) to Ad-Hoc and Sensor networks. The major goal of wireless communication is to allow users to communicate together and to have access to global network anytime anywhere. This has led to wide acceptance of infrastructure based cellular networks (WWANs) where mobile stations communicate with a centralized controller, often referred as Access Point (AP) that is connected to the wired networks. On the other hand, WLANs have appeared as dominant popular technologies in many venues including a local area such as an academic campus or an airport terminal. These wireless networks mostly rely on IEEE 802.11 Wi-Fi (Wireless Fidelity) technology and its various derived versions (i.e. 802.11a,b,g). IEEE 802.11 standard supports two operational modes: The infrastructure-based Wireless Local Area Networks (WLANs) and an infrastructure-less Ad-Hoc Networks. A WLAN (Conti, 2003) typically imposes the existence of an AP and normally is connected to the wired networks to provide internet access for mobile devices. Obviously, only one hop link is needed to communicate between mobile devices and AP. In contrast, there is no AP or infrastructure in Ad-Hoc networks. Any two stations can communicate directly when they are in the range of reception of each other. To this end, the stations may use multi-hop routing to deliver their packets to destinations. The ad-hoc protocols (Conti, 2003; Mohapatra & Krishnamurthy, 2005) are self-configured for address and routing in the face of mobility and the network topology may change in each configuration. The multi-hop wireless ad-hoc networks, or multi-hop wireless networks enable wireless networking in the environments where the wired or cellular connections are impossible, inadequate, or cost effective (e.g. battle field, disaster recovery, etc.). The popularity of internet over the last decades has resulted in rapid advancement of demanding applications. The Transmission Control Protocol/Internet Protocol (TCP/IP) (Stevens, 1994) is a well-known de facto protocol in developing today’s internet. Basically, TCP provides a connection-oriented and reliable end-to-end data delivery between two hosts in traditional wired networks. Since TCP is well tuned and due to its wide acceptance in internet, it is desirable to extend and adopt its functionality to wireless networks. On the
Read moreEnhancing the security of quality of service-oriented distributed routing protocol for hybrid wireless network
Merging the wireless infrastructure network with the wireless mobile ad-hoc networks constitutes hybrid wireless networks (HWNs). Quality of service (QoS) demands are available with the help of HWNs. However, these networks are subjected to many types of attacks because of their open wireless medium. To enhance the security of HWNs, it is necessary to provide secure routing protocols. Several routing protocols have been proposed for HWNs, one of them is the quality of service-oriented distributed (QOD) routing protocol. In this paper, two security mechanisms have been proposed for the QOD protocol. The first mechanism is used to protect transmitted data in the network using asymmetric and symmetric cryptography. The second mechanism has been proposed to enhance the security of the QOD routing protocol using keyed hash message authentication code (HMAC). The second security mechanism assumed that there is a secret key shared between each pair of neighbor nodes. Also, asymmetric cryptography is used to exchange the secret key. The secret key is used to include the message authentication code (MAC) for each message exchanged between the neighbor nodes. A network simulator NS2 is used to simulate our proposed schemes.
Read moreLightweight and Certificateless Multi-Receiver Secure Data Transmission Protocol for Wireless Body Area Networks
The rapid development of low-power integrated circuits, wireless communication, intelligent sensors, and microelectronics has allowed the realization of wireless body area networks (WBANs), which can monitor patients’ vital body parameters remotely in real time to offer timely treatment. These vital body parameters are related to patients’ life and health; and these highly private data are subject to many security threats. To guarantee privacy, many secure communication protocols have been proposed. However, most of these protocols have a one-to-one structure in extra-body communication and cannot support multidisciplinary team (MDT). Hence, we propose a lightweight and certificateless multi-receiver secure data transmission protocol for WBANs to support MDT treatment in this article. In particular, a novel multi-receiver certificateless generalized signcryption (MR-CLGSC) scheme is proposed that can adaptively use only one algorithm to implement one of three cryptographic primitives: signature, encryption or signcryption. Then, a multi-receiver secure data transmission protocol based on the MR-CLGSC scheme with many security properties, such as data integrity and confidentiality, non-repudiation, anonymity, forward and backward secrecy, unlinkability and data freshness, is designed. Both security analysis and performance analysis show that the proposed protocol for WBANs is secure, efficient, and highly practical.
Read moreSecurity-Enhanced Data Transmission With Fine-Grained and Flexible Revocation for DTWNs
The diverse properties of wireless networks are fulfilled with the assistance of digital twin (DT), which utilizes a virtual model of the physical object (PO) to provide predictions and control decisions. However, the open wireless channels and key leakage of compromised entities (including DT and PO) pose significant security issues, highlighting the need for secure data transmission schemes. Meanwhile, it is impractical to directly apply the existing works and cryptographic primitives to DT-empowered wireless networks (DTWNs) due to the absence of a solution to capture the security requirements comprehensively. Moreover, the essential characteristics for protecting historical data cannot be met. Therefore, this paper proposes a security-enhanced data transmission scheme with fine-grained and flexible revocation by customizing a novel cryptographic primitive named forward-secure puncturable signed encryption (FS-PSE). Our scheme enables confidential data dissemination/acquisition between the physical and virtual space while ensuring authentication of the real-time information and feedback results. In addition, three revocation modes are defined. Based on these modes, the entities can flexibly revoke any decryption-&-signature, decryption, and signature capability in a fine-grained approach, thereby providing security protections for the historically transmitted data even though the entity is compromised. Moreover, our scheme is instantiated with a concrete FS-PSE construction and extended to support outsourced computing to improve efficiency. Finally, the formal security proof and performance evaluation demonstrate the security and practicality of our scheme.
Read moreSecuring quality-of-service route discovery in on-demand routing for ad hoc networks
An ad hoc network is a collection of computers (nodes) that cooperate to forward packets for each other over a multihop wireless network. Users of such networks may wish to use demanding applications such as videoconferencing, Voice over IP, and streaming media when they are connected through an ad~hoc network. Because overprovisioning, a common technique in wired networks, is often impractical in wireless networks for reasons such as power, cost, and government regulation, Quality of Service (QoS) routing is even more important in wireless networks than in wired networks. Though a number of QoS-routing protocols have been proposed for use in ad~hoc networks, security of such protocols has not been considered.In this paper, we develop SQoS, a secure form of QoS-Guided Route Discovery for on-demand ad~hoc network routing. SQoS relies entirely on symmetric cryptography. Symmetric cryptographic primitives are three to four orders of magnitude faster (in computation time) than asymmetric cryptography. In addition, we show that in general, existing QoS-Guided Route Discovery can, for a single Route Discovery, transmit a number of packets exponential in the number of network nodes, creating an opportunity for Denial-of-Service (DoS) attacks. SQoS limits this overhead to be linear in the number of network nodes by providing the source with control over which Route Requests are forwarded.
Read more