Введение
Аспект криптографии
A cryptographic protocol is an abstract or concrete protocol that performs a security related function and applies cryptographic methods, often as sequences of cryptographic primitives. A protocol describes how the algorithms should be used and includes details about data structures and representations, at which point it can be used to implement multiple, interoperable versions of a program. Cryptographic protocols are widely used for secure application level data transport. A cryptographic protocol usually incorporates at least some of these aspects:
Key agreement or establishment
Entity authentication
Symmetric encryption and message authentication material construction
Secured application level data transport
Non repudiation methods
Secret sharing methods
Secure multi party computation
For example, Transport Layer Security (TLS) is a cryptographic protocol that is used to secure web (HTTPS) connections. It has an entity authentication mechanism, based on the X.509 system; a key setup phase, where a symmetric encryption key is formed by employing public key cryptography; and an application level data transport function. These three aspects have important interconnections. Standard TLS does not have non repudiation support. There are other types of cryptographic protocols as well, and even the term itself has various readings; Cryptographic application protocols often use one or more underlying key agreement methods, which are also sometimes themselves referred to as "cryptographic protocols". For instance, TLS employs what is known as the Diffie–Hellman key exchange, which although it is only a part of TLS per se, Diffie–Hellman may be seen as a complete cryptographic protocol in itself for other applications.
Криптографический протокол — это абстрактный или конкретный протокол, выполняющий функцию, связанную с безопасностью, и применяющий криптографические методы, часто в виде последовательностей криптографических примитивов. Протокол описывает, как должны использоваться алгоритмы, и включает в себя подробную информацию о структурах данных и представлениях, что позволяет использовать его для реализации нескольких совместимых версий программы. Криптографические протоколы широко используются для безопасной передачи данных на уровне приложений. Криптографический протокол обычно включает в себя как минимум некоторые из следующих аспектов:
A cryptographic protocol is an abstract or concrete protocol that performs a security related function and applies cryptographic methods, often as sequences of cryptographic primitives. A protocol describes how the algorithms should be used and includes details about data structures and representations, at which point it can be used to implement multiple, interoperable versions of a program. Cryptographic protocols are widely used for secure application level data transport. A cryptographic protocol usually incorporates at least some of these aspects:
Key agreement or establishment
Entity authentication
Symmetric encryption and message authentication material construction
Secured application level data transport
Non repudiation methods
Secret sharing methods
Secure multi party computation
For example, Transport Layer Security (TLS) is a cryptographic protocol that is used to secure web (HTTPS) connections. It has an entity authentication mechanism, based on the X.509 system; a key setup phase, where a symmetric encryption key is formed by employing public key cryptography; and an application level data transport function. These three aspects have important interconnections. Standard TLS does not have non repudiation support. There are other types of cryptographic protocols as well, and even the term itself has various readings; Cryptographic application protocols often use one or more underlying key agreement methods, which are also sometimes themselves referred to as "cryptographic protocols". For instance, TLS employs what is known as the Diffie–Hellman key exchange, which although it is only a part of TLS per se, Diffie–Hellman may be seen as a complete cryptographic protocol in itself for other applications.
Согласование или установление ключей
Аутентификация сущностей
Симметричное шифрование и построение материала для аутентификации сообщений
Безопасная передача данных на уровне приложений
Методы предотвращения отказа
Методы обмена секретами
Безопасные многосторонние вычисления
A cryptographic protocol is an abstract or concrete protocol that performs a security related function and applies cryptographic methods, often as sequences of cryptographic primitives. A protocol describes how the algorithms should be used and includes details about data structures and representations, at which point it can be used to implement multiple, interoperable versions of a program. Cryptographic protocols are widely used for secure application level data transport. A cryptographic protocol usually incorporates at least some of these aspects:
Key agreement or establishment
Entity authentication
Symmetric encryption and message authentication material construction
Secured application level data transport
Non repudiation methods
Secret sharing methods
Secure multi party computation
For example, Transport Layer Security (TLS) is a cryptographic protocol that is used to secure web (HTTPS) connections. It has an entity authentication mechanism, based on the X.509 system; a key setup phase, where a symmetric encryption key is formed by employing public key cryptography; and an application level data transport function. These three aspects have important interconnections. Standard TLS does not have non repudiation support. There are other types of cryptographic protocols as well, and even the term itself has various readings; Cryptographic application protocols often use one or more underlying key agreement methods, which are also sometimes themselves referred to as "cryptographic protocols". For instance, TLS employs what is known as the Diffie–Hellman key exchange, which although it is only a part of TLS per se, Diffie–Hellman may be seen as a complete cryptographic protocol in itself for other applications.
Например, Transport Layer Security (TLS) — это криптографический протокол, используемый для защиты веб-соединений (HTTPS). Он имеет механизм аутентификации сущностей, основанный на системе X.509; фазу настройки ключа, на которой симметричный ключ шифрования формируется с использованием криптографии с открытым ключом; и функцию передачи данных на уровне приложений. Эти три аспекта тесно взаимосвязаны. Стандартный TLS не поддерживает неотрекаемость. Существуют и другие типы криптографических протоколов, и даже сам термин имеет различные интерпретации. Криптографические протоколы приложений часто используют один или несколько базовых методов согласования ключей, которые также иногда называют «криптографическими протоколами». Например, TLS использует так называемый обмен ключами Диффи — Хеллмана, который, хотя и является лишь частью TLS как такового, может рассматриваться как самостоятельный криптографический протокол для других приложений.
A cryptographic protocol is an abstract or concrete protocol that performs a security related function and applies cryptographic methods, often as sequences of cryptographic primitives. A protocol describes how the algorithms should be used and includes details about data structures and representations, at which point it can be used to implement multiple, interoperable versions of a program. Cryptographic protocols are widely used for secure application level data transport. A cryptographic protocol usually incorporates at least some of these aspects:
Key agreement or establishment
Entity authentication
Symmetric encryption and message authentication material construction
Secured application level data transport
Non repudiation methods
Secret sharing methods
Secure multi party computation
For example, Transport Layer Security (TLS) is a cryptographic protocol that is used to secure web (HTTPS) connections. It has an entity authentication mechanism, based on the X.509 system; a key setup phase, where a symmetric encryption key is formed by employing public key cryptography; and an application level data transport function. These three aspects have important interconnections. Standard TLS does not have non repudiation support. There are other types of cryptographic protocols as well, and even the term itself has various readings; Cryptographic application protocols often use one or more underlying key agreement methods, which are also sometimes themselves referred to as "cryptographic protocols". For instance, TLS employs what is known as the Diffie–Hellman key exchange, which although it is only a part of TLS per se, Diffie–Hellman may be seen as a complete cryptographic protocol in itself for other applications.
Продвинутые криптографические протоколы
Широкий спектр криптографических протоколов выходит за рамки традиционных целей обеспечения конфиденциальности, целостности и аутентичности данных, чтобы также обеспечить различные другие желаемые характеристики при компьютерном взаимодействии. Слепые подписи могут использоваться для цифровых денег и цифровых удостоверений, чтобы доказать, что человек обладает определенным атрибутом или правом, не раскрывая его личность или личности сторон, с которыми он взаимодействовал. Безопасная цифровая временная метка может использоваться для доказательства существования данных (даже конфиденциальных) в определенный момент времени. Безопасные многосторонние вычисления позволяют вычислять результаты (например, определять самую высокую ставку на аукционе) на основе конфиденциальных данных (например, частных предложений) таким образом, что после завершения протокола участники знают только свой собственный вклад и результат. Системы электронного голосования с возможностью аудита обеспечивают желаемые свойства конфиденциальности и аудируемости для проведения электронного голосования. Неопровержимые подписи включают интерактивные протоколы, позволяющие подписанту доказать факт подделки и ограничить круг лиц, имеющих право проверять подпись. Отрицаемое шифрование дополняет стандартное шифрование, делая невозможным для злоумышленника математически доказать существование исходного сообщения. Цифровые смеси создают коммуникации, которые трудно отследить.
Понятие абстрактного протокола
Для формальной проверки протокола его часто абстрагируют и моделируют, используя обозначения Алисы и Боба. Простой пример выглядит следующим образом:
Это означает, что Алиса намерена отправить Бобу сообщение, состоящее из сообщения, зашифрованного общим ключом.