惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
The Cloudflare Blog
G
Google Developers Blog
博客园_首页
Martin Fowler
Martin Fowler
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
D
Docker
C
Check Point Blog
T
Tailwind CSS Blog
博客园 - 司徒正美
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
Microsoft Security Blog
Microsoft Security Blog
V
V2EX
博客园 - 叶小钗
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
IT之家
IT之家
M
MIT News - Artificial intelligence
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 【当耐特】
GbyAI
GbyAI

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model? Applications of Bruhat-Chevalley-Renner Decomposition to Metric-Aware Code-Based Cryptography
Ghost of Sessions Past: Distributed and Forward Secure Ke...
Roozbeh Sare · 2025-12-24 · via Cryptology ePrint Archive

Paper 2025/2322

Ghost of Sessions Past: Distributed and Forward Secure Key Establishment for Implantable Medical Devices

Sayon Duttagupta, COSIC, KU Leuven

Kevin Bogner, COSIC, KU Leuven

Varesh Mishra, COSIC, KU Leuven

Francesco Milizia, Sapienza University of Rome

Bart Preneel, COSIC, KU Leuven

Abstract

Implantable Medical Devices (IMDs) operate for decades in dynamic and adversarial environments, where device loss, backend compromise, and eventual post-explantation access are realistic long-term threats. Existing IMD security mechanisms largely focus on secure pairing and access control, but rely on long-lived secrets. As a result, a compromise occurring years after deployment can retroactively expose previously recorded patient telemetry. Limiting such damage requires forward secrecy. However, achieving forward secrecy in IMDs is challenging due to strict energy constraints, intermittent connectivity, and safety requirements, which make frequent public-key operations on the implant impractical. We present \emph{Chronos}, a distributed, symmetric-only key establishment protocol that provides forward secrecy for IMDs without requiring public-key cryptography on the implant. \emph{Chronos} evolves cryptographic state across sessions using lightweight primitives on the device, ensuring that past communications remain confidential even under post-compromise exposure. State consistency, resynchronisation, and recovery are coordinated by a threshold-based distributed backend, eliminating single points of failure and enabling controlled emergency operation when the user's device is unavailable, while preserving patient-centric access control. We formally analyse \emph{Chronos} using ProVerif under a Dolev--Yao adversary with post-session compromise capabilities, establishing secrecy, agreement, forward secrecy, and correctness of emergency and recovery mechanisms. We implement \emph{Chronos} end-to-end, including an Android client, distributed backend services, and implant-side firmware on both a 16-bit MSP430 and a 32-bit ARM Cortex-M33 microcontroller. Our evaluation shows that forward secrecy with recovery from state inconsistency is achievable within realistic IMD constraints, with negligible impact on device energy budgets even under pessimistic usage assumptions.

BibTeX

@misc{cryptoeprint:2025/2322,
      author = {Roozbeh Sarenche and Sayon Duttagupta and Kevin Bogner and Varesh Mishra and Francesco Milizia and Bart Preneel},
      title = {Ghost of Sessions Past: Distributed and Forward Secure Key Establishment for Implantable Medical Devices},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2322},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2322}
}