慣性聚合 高效追蹤和閱讀你感興趣的部落格、新聞、科技資訊
閱讀原文 在慣性聚合中打開

推薦訂閱源

Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
M
MIT News - Artificial intelligence
博客园 - 叶小钗
MyScale Blog
MyScale Blog
V
Visual Studio Blog
月光博客
月光博客
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
量子位
I
InfoQ
有赞技术团队
有赞技术团队
阮一峰的网络日志
阮一峰的网络日志
Jina AI
Jina AI
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
雷峰网
雷峰网
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky

Cryptology ePrint Archive

Dynamic Group Time-based One-time Passwords MBU: Scalable and Constant-Round Evaluation of Non-linear Functions in Standard MPC Setting CEDAR: A Compact and Efficient Decoder Architecture for RS-RM Code in HQC LEAH: Lightweight and Efficient Hardware Accelerator for Code-based PQC Scheme HQC The Sum-Check Protocol over the Monomial Basis, and Other Optimizations How to Authenticate a Non-Deterministic Computation Fully Adaptive Threshold Blind Signature Without AGM Additive FFTs for HQC on ARM Cortex-M4, Revisited SPoCK: Sequential Proofs of Complete Knowledge Blind Verifiable Delay Functions Compact Fully Asynchronous Updatable Public Key Encryption Scheme from Hamming Quasi-Cyclic Cryptosystem CLAASP-MP: An Automated MILP Framework for Monomial Prediction Assessing Geometric Security of AES Neural Realizations: Linear-Time Key Recovery via Neural Leakage Explicit Bounds on the Existence Probability of Random Multivariate Quadratic Systems over Finite Fields Faster Logical Operations from Discrete CKKS SecDTD: Dynamic Token Drop for Secure Transformers Inference Towards Zero Rotation and Beyond: Architecting Neural Networks for Fast Secure Inference with Homomorphic Encryption Code-based Scalable Collaborative SNARKs MAGNET: MAsked Gaussian Now Efficient and Table-less Automated formal analysis of Signal’s Double Ratchet: attacks, fixes and security proofs Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits The Cost of Fluidity: Communication Complexity Trade-offs in Fluid MPC Decomposition of Large Look-Up Tables for Fast Homomorphic Evaluation Hint-Free Multi-Signatures (Mis)using the Lattice Isomorphism Problem. Cryptanalysis of the double-LIP and Construction of LIP-Based Blind Signatures Improving LatticeFold+ with ℓ2-norm Checks ABRA-CAPA-DABRA: Full break of CAPA Polynomial-Time Cryptanalytic Extraction of Graph Neural Networks in the Hard-Label Setting Zero-Knowledge Proof of Progress: Secure Multi-Phase Capture-the-Flag Competitions Scalable Registration-Based Encryption from Lattices ISE-supported erasure of residual shares Chorus: Secret Recovery with Ephemeral Client Committees $\mathsf{Veloz}$: Efficient and Flexible Distribution Framework for Code-Based Polynomial Commitment Scheme How to construct even faster and indifferentiable hash functions from random permutations Public Key Encryption from High-Corruption Constraint Satisfaction Problems Drop-In Masked Modular Reduction for ML-DSA: Cutting Side-Channel Cost in the Root-of-Trust Optimizing and Implementing Threshold MAYO Improved Cryptanalysis of the Permuted Kernel Problem with Applications to PERK v2.2.0, SUSHSYFISH and PKP-DSS Cross-Paradigm Models of Restricted Syndrome Decoding with Application to CROSS Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies
誠實用戶會犯誠實的錯誤:一個分析電子身份識別協議的框架
Ole Martin E · 2025-09-17 · via Cryptology ePrint Archive

論文 2025/1686

誠實使用者會犯誠實的錯誤:一個分析電子身份識別協議的框架

Kristian Gjøsteen,挪威科學與技術大學

Hans Heum,挪威科學與技術大學

Sjouke Mauw,盧森堡大學

Felix Stutz 路易斯維爾大學

摘要

電子識別 (eID) 協議與聯邦身分管理系統在我們現代社會中扮演越來越重要的角色,透過 Google 與其他服務在網路上,以及透過歐洲的 eIDAS 法規。eID 協議的一個關鍵特點是人在協議中深度參與,通常負責關鍵的安全步驟。傳統的安全分析通常假設使用者行為完美無缺,但廣泛的實際應用使得使用者的錯誤不可避免。 我們提出了一個分析 eID 協議安全的框架,可以模擬使用者犯錯。它適合使用 Tamarin 進行自動化分析,並支援對協議參與者的細粒度腐化模擬。我們透過描述和分析基於密碼、移動應用程式和驗證憑據的常見 eID 協議,以及系統性地評估各種使用者錯誤組合對安全的影響,來展示該框架的用途。

BibTeX

@misc{cryptoeprint:2025/1686,
      author = {Ole Martin Edstrøm and Kristian Gjøsteen and Hans Heum and Sjouke Mauw and Felix Stutz},
      title = {Honest Users Make Honest Mistakes: A Framework for Analysing {eID} Protocols},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1686},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1686}
}