Title
A Modular Treatment of Cryptographic APIs: The Symmetric-Key Case.
Abstract
Application Programming Interfaces APIs to cryptographic tokens like smartcards and Hardware Security Modules HSMs provide users with commands to manage and use cryptographic keys stored on trusted hardware. Their design is mainly guided by industrial standards with only informal security promises. In this paper we propose cryptographic models for the security of such APIs. The key feature of our approach is that it enables modular analysis. Specifically, we show that a secure cryptographic API can be obtained by combining a secure API for key-management together with secure implementations of, for instance, encryption or message authentication. Our models are the first to provide such compositional guarantees while considering realistic adversaries that can adaptively corrupt keys stored on tokens. We also provide a proof of concept instantiation from a deterministic authenticated-encryption scheme of the key-management portion of cryptographic API.
Year
DOI
Venue
2016
10.1007/978-3-662-53018-4_11
IACR Cryptology ePrint Archive
DocType
Volume
ISSN
Conference
2016
0302-9743
Citations 
PageRank 
References 
3
0.42
17
Authors
3
Name
Order
Citations
PageRank
Thomas Shrimpton1132060.19
Martijn Stam2165967.36
Bogdan Warinschi3151468.98