Password-Protected Key Retrieval with(out) HSM Protection
Sebastian H. Faller, Tobias Handirk, Julia Hesse, Máté Horváth, Anja Lehmann
摘要
Password-protected key retrieval (PPKR) enables users to store and retrieve high-entropy keys from a server securely. The process is bootstrapped from a human-memorizable password only, addressing the challenge of how end-users can manage cryptographic key material. The core security requirement is protection against a corrupt server, which should not be able to learn the key or offlineattack it through the password protection. PPKR is deployed at a large scale with the WhatsApp Backup Protocol (WBP), allowing users to access their encrypted messaging history when switching to a new device. Davies et al. (Crypto'23) formally analyzed the WBP, proving that it satisfies most of the desired security. The WBP uses the OPAQUE protocol for password-based key exchange as a building block and relies on the server using a hardware security module (HSM) for most of its protection. In fact, the security analysis assumes that the HSM is incorruptible -rendering most of the heavy cryptography in the WBP obsolete. In this work, we explore how provably secure and efficient PPKR can be built that either relies strongly on an HSM -but then takes full advantage of that -or requires less trust assumption for the price of more advanced cryptography. To this end, we expand the definitional work by Davies et al. to allow the analysis of PPKR with fine-grained HSM corruption, such as leakage of user records or attestation keys. For each scenario, we aim to give minimal PPKR solutions. For the strongest corruption setting, namely a fully corrupted HSM, we propose a protocol with a simpler design and better efficiency than the WBP. We also fix an attack related to client authentication that was identified by Davies et al. CCS Concepts • Security and privacy → Key management; Public key (asymmetric) techniques.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper6
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- DiSE: Distributed Symmetric-key EncryptionShashank Agrawal, Payman Mohassel, Pratyay Mukherjee, Peter RindalCCS 2018 · 被引用 45 次
- Security Analysis of the WhatsApp End-to-End Encrypted Backup ProtocolGareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk 等CRYPTO 2023 · 被引用 29 次
- Trust Dies in Darkness: Shedding Light on Samsung's TrustZone Keymaster DesignAlon Shakevsky, Eyal Ronen, Avishai WoolUSENIX Security 2022
- How to Recover a Cryptographic Secret From the CloudDavid Adei, Chris Orsini, Alessandra Scafuro, Tanner VerberCCS 2025
相关 Paper
- Simple Password-Hardened Encryption ServicesRussell W. F. Lai, Christoph Egger, Manuel Reinert, Sherman S. M. Chow 等USENIX Security 2018 · 被引用 33 次
- End-to-Same-End Encryption: Modularly Augmenting an App with an Efficient, Portable, and Blind Cloud StorageLong Chen, Ya-Nan Li, Qiang Tang, Moti YungUSENIX Security 2022
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 被引用 2 次
- KHAPE: Asymmetric PAKE from Key-Hiding Key ExchangeYanqi Gu, Stanislaw Jarecki, Hugo KrawczykCRYPTO 2021 · 被引用 34 次
- Threshold Password-Hardened Encryption ServicesJulian Brost, Christoph Egger, Russell W. F. Lai, Fritz Schmid 等CCS 2020 · 被引用 24 次
