12
M. Kutyłowski et al.
The rest of this section is devoted to diverse methods that at least reduce the
privacy risks without retreating to asymmetric cryptography.
1.3.1 Symmetric Protocols and Deniability
From the point of view of privacy protection, symmetric cryptography leads to fewer
problems than advanced methods based on asymmetric cryptography. Namely, if
all cryptographic secrets used to execute a protocol are available to both parties
executing the protocol, then a valid transcript of a protocol execution can be created
by either party of the protocol. Therefore such a transcript cannot be used as a proof
that an interaction has taken place.
Let us note that the situation might be different if a secret for symmetric
cryptography is known only to one party of the protocol. For instance, if a device D
is authenticated by presenting a token s, where Hash(s) is a one-time key publicly
known as belonging to D, then presenting s may serve as a proof that an interaction
with D has taken place.
1.3.2 Identity Hiding with Random Key Predistribution
When tools such as Diffie-Hellman key exchange are unavailable, random key
predistribution may help to protect the initial information exchange. According to
this approach, a session is initiated as follows:
Phase 1 (key discovery): the communicating devices find keys from the key
predistribution scheme that they share,
Phase 2 (identity disclosure): the devices exchange their identity information,
and communication is protected with the shared keys found in Phase 1,
Phase 3 (authentication and key establishment): the devices continue in a way
tailored to the declared identity information, encryption may be based on bilateral
keys and not on the keys from the key predistribution.
Let us recall a few details of key predistribution schemes. There is a global key
pool K of size N. We assume that each device i has an individual key pool K (i)
consisting of keys k
(i)
1 , . . . , k
(i)
n . If devices i and j meet, they identify a key (or
keys) in K (i) ∩ K (j) (shared keys).
There are certain details about how to choose the subsets of keys to ensure that
the set of keys K (i) ∩ K (j) is nonempty. The basic approach is to choose random
subsets—then due to the birthday paradox there is a fair chance of a key being
shared if n ≈
√
N . Another approach is to consider a projective space and assign
keys corresponding to a line to each device—note that in a projective space every
two lines intersect [124].
Précédent

- 27/268

Suivant