인셔셔RSS 관심 있는 블로그, 뉴스, 기술 정보를 효율적으로 추적하고 읽으세요
원문 읽기 InertiaRSS에서 열기

추천 피드

Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
M
MIT News - Artificial intelligence
博客园 - 叶小钗
MyScale Blog
MyScale Blog
V
Visual Studio Blog
月光博客
月光博客
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
量子位
I
InfoQ
有赞技术团队
有赞技术团队
阮一峰的网络日志
阮一峰的网络日志
Jina AI
Jina AI
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
雷峰网
雷峰网
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky

Cryptology ePrint Archive

Dynamic Group Time-based One-time Passwords MBU: Scalable and Constant-Round Evaluation of Non-linear Functions in Standard MPC Setting CEDAR: A Compact and Efficient Decoder Architecture for RS-RM Code in HQC LEAH: Lightweight and Efficient Hardware Accelerator for Code-based PQC Scheme HQC The Sum-Check Protocol over the Monomial Basis, and Other Optimizations How to Authenticate a Non-Deterministic Computation Fully Adaptive Threshold Blind Signature Without AGM Additive FFTs for HQC on ARM Cortex-M4, Revisited SPoCK: Sequential Proofs of Complete Knowledge Blind Verifiable Delay Functions Compact Fully Asynchronous Updatable Public Key Encryption Scheme from Hamming Quasi-Cyclic Cryptosystem CLAASP-MP: An Automated MILP Framework for Monomial Prediction Assessing Geometric Security of AES Neural Realizations: Linear-Time Key Recovery via Neural Leakage Explicit Bounds on the Existence Probability of Random Multivariate Quadratic Systems over Finite Fields Faster Logical Operations from Discrete CKKS SecDTD: Dynamic Token Drop for Secure Transformers Inference Towards Zero Rotation and Beyond: Architecting Neural Networks for Fast Secure Inference with Homomorphic Encryption Code-based Scalable Collaborative SNARKs MAGNET: MAsked Gaussian Now Efficient and Table-less Automated formal analysis of Signal’s Double Ratchet: attacks, fixes and security proofs Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits The Cost of Fluidity: Communication Complexity Trade-offs in Fluid MPC Decomposition of Large Look-Up Tables for Fast Homomorphic Evaluation Hint-Free Multi-Signatures (Mis)using the Lattice Isomorphism Problem. Cryptanalysis of the double-LIP and Construction of LIP-Based Blind Signatures Improving LatticeFold+ with ℓ2-norm Checks ABRA-CAPA-DABRA: Full break of CAPA Polynomial-Time Cryptanalytic Extraction of Graph Neural Networks in the Hard-Label Setting Zero-Knowledge Proof of Progress: Secure Multi-Phase Capture-the-Flag Competitions Scalable Registration-Based Encryption from Lattices ISE-supported erasure of residual shares Chorus: Secret Recovery with Ephemeral Client Committees $\mathsf{Veloz}$: Efficient and Flexible Distribution Framework for Code-Based Polynomial Commitment Scheme How to construct even faster and indifferentiable hash functions from random permutations Public Key Encryption from High-Corruption Constraint Satisfaction Problems Drop-In Masked Modular Reduction for ML-DSA: Cutting Side-Channel Cost in the Root-of-Trust Optimizing and Implementing Threshold MAYO Improved Cryptanalysis of the Permuted Kernel Problem with Applications to PERK v2.2.0, SUSHSYFISH and PKP-DSS Cross-Paradigm Models of Restricted Syndrome Decoding with Application to CROSS Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies
성실한 사용자는 성실한 실수를 합니다: eID 프로토콜 분석을 위한 프레임워크
Ole Martin E · 2025-09-17 · via Cryptology ePrint Archive

논문 2025/1686

성실한 사용자는 성실한 실수를 합니다: eID 프로토콜 분석을 위한 프레임워크

크리스티안 그제스트, 노르웨이 과학 기술 대학교

한스 후엄, 노르웨이 과학 기술 대학교

슐뢰크 마우, 루크스라무르 대학교

펠릭 슈투츠 루크셉 공과대학교

요약

디지털 식별자(eID) 프로토콜과 페더레이티드 식별자 관리 시스템은 우리 현대 사회에서 점점 더 중요한 역할을 하고 있습니다. 구글 등의 서비스를 통해 인터넷에서도 그렇고, 유럽의 eIDAS 규정을 통해도 그렇습니다. eID 프로토콜의 주요 특징은 인간이 프로토콜에 깊숙이 관여하고, 종종 중요한 보안 단계를 책임지는 것입니다. 이러한 프로토콜의 전통적인 보안 분석은 사용자 행동이 완벽하다고 가정하는 경우가 많지만, 광범위한 실제 세계 도입은 사용자의 실수를 피할 수 없게 합니다. 우리는 실수를 하는 사용자를 모델링할 수 있는 eID 프로토콜의 보안을 분석하는 프레임워크를 제시합니다. Tamarin을 사용한 자동 분석에 적합하며, 프로토콜 주체의 미세한 손상 모델링을 지원합니다. 우리는 비밀번호, 모바일 애플리케이션 및 인증 토큰을 기반으로 한 일반적인 eID 프로토콜을 설명하고 분석하여 프레임워크의 유용성을 입증하고, 다양한 사용자 실수 조합이 보안에 미치는 영향을 체계적으로 평가합니다.

BibTeX

@misc{cryptoeprint:2025/1686,
      author = {Ole Martin Edstrøm and Kristian Gjøsteen and Hans Heum and Sjouke Mauw and Felix Stutz},
      title = {Honest Users Make Honest Mistakes: A Framework for Analysing {eID} Protocols},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1686},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1686}
}