1 Emerging Security Challenges for Ubiquitous Devices
7
symmetric cryptography) or disclosing r. However, revealing the committed value
must not occur before the moment when this value is transmitted to the Reader.
Indeed, the Watchdog might transfer this value prematurely—we cannot exclude
the possibility that the Watchdog and the Reader are colluding.
Recall that randomization of the hash argument is easy for Pedersen commitments:
• the Device chooses r and s at random and computes c := g r · h s , it presents
c to the Watchdog,
• the Watchdog chooses r , s at random computes c := c · g r · h s and:
– sends r , s to the Device,
– sends the commitment c to the Reader,
• the Device computes the committed values: r := r · r , s := s · s .
Unfortunately, such commitments require implementing asymmetric cryptography,
while we have assumed that we are limited to symmetric methods. Concluding, as
it seems very hard to overcome the problems related to hash functions that are not
based on asymmetric cryptography, we must focus on symmetric encryption. Note
that symmetric encryption has to be implemented on most ubiquitous devices to
encrypt messages, so reusing it for commitments may reduce the implementation
cost and simplify the hardware requirements.
1.2.3.2 Commitments Based on Symmetric Encryption
We assume that the encryption function works with n-bit keys and converts n-bit
blocks into n-bit ciphertexts. Hence each key defines a permutation on n-bit blocks.
We assume that the encryption scheme is resistant to known-plaintext attacks.
The second assumption is that given a ciphertext c, for most plaintexts t there is
a key k such that c = Enc k (t).
Basic Commitment Mechanism
1. choose a plaintext t and a key k at random,
2. compute c := Enc k (t),
3. present (t, c) as a commitment for k.
In order to open the commitment (t, c) one has to present k. The commitment
opening test is Enc k (t)
?
= c. Note that breaking the commitment is equivalent to a
successful known-plaintext attack. Of course some care is required when choosing
the encryption scheme, as each single bit of the key has to be secure against
cryptanalysis.
Controlled Commitment Mechanism
1. The Device creates a commitment (t , c ) for k using the basic mechanism
(i.e., c := Enc k (t ) and t is a single n-bit block), and presents (t , c ) to the
Watchdog,
Précédent

- 22/268

Suivant