Applied Cryptography and Network Security: 7th International by Mark Manulis (auth.), Michel Abdalla, David Pointcheval,

By Mark Manulis (auth.), Michel Abdalla, David Pointcheval, Pierre-Alain Fouque, Damien Vergnaud (eds.)

This e-book constitutes the refereed lawsuits of the seventh foreign convention on utilized Cryptography and community defense, ACNS 2009, held in Paris-Rocquencourt, France, in June 2009.

The 32 revised complete papers provided have been conscientiously reviewed and chosen from one hundred fifty submissions. The papers are geared up in topical sections on key trade, safe computation, public-key encryption, community safety, traitor tracing, authentication and anonymity, hash fundtions, lattices, and side-channel attacks.

This effect is not captured by the definition of Ephemeral Key Reveal, which is the ultimate problem with the reduction from Session-state Reveal to Ephemeral Key Reveal, as was already noted in [13]. The attacks presented in this paper exploit exactly this difference. A possible practical interpretation of the difference between the models is the following. The CK model considers a TPM implementation, where parts of the protocol are computed in unprotected memory, specified by the contents of the session-state, but the long-term private keys are protected by the TPM.

Many of the proposed protocols have been shown to be correct in some particular security model, but have also shown to be incorrect in others. In order to determine the exact properties that are required from such protocols, a single unified security model would be desirable. However, given the recent works such as [8], it seems that a single model is still not agreed upon. In this paper we focus on a specific aspect of security models for key agreement protocols. In particular, we focus on the ability of the adversary to learn the local state of an agent.

