Lune

EUROCRYPT2021顶会

Analysing the HPKE Standard

Joël Alwen, Bruno Blanchet, Eduard Hauck, Eike Kiltz, Benjamin Lipp, Doreen Riepel

2021年份
29被引次数
10顶会引用

摘要

The Hybrid Public Key Encryption (HPKE) scheme is an emerging standard currently under consideration by the Crypto Forum Research Group (CFRG) of the IETF as a candidate for formal approval. Of the four modes of HPKE, we analyse the authenticated mode HPKEAuth\mathsf {HPKE}_\mathsf {Auth} in its single-shot encryption form as it contains what is, arguably, the most novel part of HPKE. HPKEAuth\mathsf {HPKE}_\mathsf {Auth} ’s intended application domain is captured by a new primitive which we call Authenticated Public Key Encryption (APKE). We provide syntax and security definitions for APKE schemes, as well as for the related Authenticated Key Encapsulation Mechanisms (AKEMs). We prove security of the AKEM scheme DH-AKEM\mathsf {DH}\hbox {-}\mathsf {AKEM} underlying HPKEAuth\mathsf {HPKE}_\mathsf {Auth} based on the Gap Diffie-Hellman assumption and provide general AKEM/DEM composition theorems with which to argue about HPKEAuth\mathsf {HPKE}_\mathsf {Auth} ’s security. To this end, we also formally analyse HPKEAuth\mathsf {HPKE}_\mathsf {Auth} ’s key schedule and key derivation functions. To increase confidence in our results we use the automatic theorem proving tool CryptoVerif. All our bounds are quantitative and we discuss their practical implications for HPKEAuth\mathsf {HPKE}_\mathsf {Auth} . As an independent contribution we propose the new framework of nominal groups that allows us to capture abstract syntactical and security properties of practical elliptic curves, including the Curve25519 and Curve448 based groups (which do not constitute cyclic groups).

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper10

问问它们各自怎么用它

它引用的顶会 Paper2

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖