Key recycling in authentication
arXiv:1202.1229 · doi:10.1109/TIT.2014.2317312
Abstract
In their seminal work on authentication, Wegman and Carter propose that to authenticate multiple messages, it is sufficient to reuse the same hash function as long as each tag is encrypted with a one-time pad. They argue that because the one-time pad is perfectly hiding, the hash function used remains completely unknown to the adversary. Since their proof is not composable, we revisit it using a composable security framework. It turns out that the above argument is insufficient: if the adversary learns whether a corrupted message was accepted or rejected, information about the hash function is leaked, and after a bounded finite amount of rounds it is completely known. We show however that this leak is very small: Wegman and Carter's protocol is still -secure, if -almost strongly universal hash functions are used. This implies that the secret key corresponding to the choice of hash function can be reused in the next round of authentication without any additional error than this . We also show that if the players have a mild form of synchronization, namely that the receiver knows when a message should be received, the key can be recycled for any arbitrary task, not only new rounds of authentication.
17+3 pages. 11 figures. v3: Rewritten with AC instead of UC. Extended the main result to both synchronous and asynchronous networks. Matches published version up to layout and updated references. v2: updated introduction and references
References in corpus (4)
Cited by in corpus (25)
- Security in Quantum Cryptography
- Distributing Secret Keys with Quantum Continuous Variables: Principle, Security and Implementations
- A fast and versatile QKD system with hardware key distillation and wavelength multiplexing
- A Novel Approach to Quality of Service Provisioning in Trusted Relay Quantum Key Distribution Networks
- Lightweight authentication for quantum key distribution
- Attacks on quantum key distribution protocols that employ non-ITS authentication
- Quantum authentication with key recycling
- Causal Boxes: Quantum Information-Processing Systems Closed under Composition
- Scalable authentication and optimal flooding in a quantum network
- Experimental quantum key distribution certified by Bell's theorem
- The Universal Composable Security of Quantum Message Authentication with Key Recyling
- Essential lack of security proof in quantum key distribution
- Practical quantum multiparty signatures using quantum-key-distribution networks
- Quantum and semi-quantum sealed-bid auction: Vulnerabilities and advantages
- A consolidated and accessible security proof for finite-size decoy-state quantum key distribution
- Entanglement-assisted authenticated BB84 protocol
- (Quantum) Min-Entropy Resources
- Wellposedness and regularity of steady-state two-sided variable-coefficient conservative space-fractional diffusion equations
- Quantum Key Recycling with Optimal Key Recycling Rate based on Error Rate
- Incorporating device characterization into security proofs
- High-speed Privacy Amplification Scheme using GMP in Quantum Key Distribution
- QKD parameter estimation by two-universal hashing
- Security of Quantum Key Distribution
- Efficient Bit Sifting Scheme of Post-processing in Quantum Key Distribution
- Security proofs for practical QKD: variations, techniques, gaps, and limitations