A robust security framework with bit-flipping attack and timing attack for key derivation functions

A Key Derivation Function (KDF) derives cryptographic keys from private string and public information. The security property for the cryptographic keys is indistinguishable from the random strings of equal length. The security analysis of KDFs has received increasing attention. The practice importan...

Full description

Saved in:
Bibliographic Details
Main Authors: Wen Koh, Wen, Wen Chuah, Chai
Format: Article
Language:en
Published: Institution of Engineering and Technology (IET) / Wiley Open Access 2020
Subjects:
Online Access:http://eprints.uthm.edu.my/6534/1/AJ%202020%20%28331%29.pdf
http://eprints.uthm.edu.my/6534/
https://doi.org/10.1049/iet-ifs.2019.0163
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1833418120112373760
author Wen Koh, Wen
Wen Chuah, Chai
author_facet Wen Koh, Wen
Wen Chuah, Chai
author_sort Wen Koh, Wen
building UTHM Library
collection Institutional Repository
content_provider Universiti Tun Hussein Onn Malaysia
content_source UTHM Institutional Repository
continent Asia
country Malaysia
description A Key Derivation Function (KDF) derives cryptographic keys from private string and public information. The security property for the cryptographic keys is indistinguishable from the random strings of equal length. The security analysis of KDFs has received increasing attention. The practice important of KDFs are reflected in the adoption of industry standards such as NIST800-135 and PKCS5. This paper proposes a robust security framework which takes into consideration the side channel attacks. The robust security framework consists of the proposed security model and existing security models. The proposed security model is known as Adaptive Chosen All Inputs Model (CAM) which analyses the security of KDFs in terms of the bit-flipping attack and timing attack. The existing security model is the Adaptive Chosen Public Inputs Model (CPM). This research shows the implication relationship and non-implication relationship between CAM and CPM. The simulation of security models is according to the indistinguishable game played between a challenger and an adversary. These security models are used to evaluate existing KDFs. The result shows that none of the existing KDFs are secure in CAM for both the bit-flipping attack and timing attack. Hence, this research introduces an alternative KDF that is proven secure in CAM.
format Article
id my.uthm.eprints-6534
institution Universiti Tun Hussein Onn Malaysia
language en
publishDate 2020
publisher Institution of Engineering and Technology (IET) / Wiley Open Access
record_format eprints
spelling my.uthm.eprints-65342022-02-28T06:51:46Z http://eprints.uthm.edu.my/6534/ A robust security framework with bit-flipping attack and timing attack for key derivation functions Wen Koh, Wen Wen Chuah, Chai T175-178 Industrial research. Research and development A Key Derivation Function (KDF) derives cryptographic keys from private string and public information. The security property for the cryptographic keys is indistinguishable from the random strings of equal length. The security analysis of KDFs has received increasing attention. The practice important of KDFs are reflected in the adoption of industry standards such as NIST800-135 and PKCS5. This paper proposes a robust security framework which takes into consideration the side channel attacks. The robust security framework consists of the proposed security model and existing security models. The proposed security model is known as Adaptive Chosen All Inputs Model (CAM) which analyses the security of KDFs in terms of the bit-flipping attack and timing attack. The existing security model is the Adaptive Chosen Public Inputs Model (CPM). This research shows the implication relationship and non-implication relationship between CAM and CPM. The simulation of security models is according to the indistinguishable game played between a challenger and an adversary. These security models are used to evaluate existing KDFs. The result shows that none of the existing KDFs are secure in CAM for both the bit-flipping attack and timing attack. Hence, this research introduces an alternative KDF that is proven secure in CAM. Institution of Engineering and Technology (IET) / Wiley Open Access 2020 Article PeerReviewed text en http://eprints.uthm.edu.my/6534/1/AJ%202020%20%28331%29.pdf Wen Koh, Wen and Wen Chuah, Chai (2020) A robust security framework with bit-flipping attack and timing attack for key derivation functions. IET Information Security, 14 (5). pp. 562-571. ISSN 1751-8709 https://doi.org/10.1049/iet-ifs.2019.0163
spellingShingle T175-178 Industrial research. Research and development
Wen Koh, Wen
Wen Chuah, Chai
A robust security framework with bit-flipping attack and timing attack for key derivation functions
title A robust security framework with bit-flipping attack and timing attack for key derivation functions
title_full A robust security framework with bit-flipping attack and timing attack for key derivation functions
title_fullStr A robust security framework with bit-flipping attack and timing attack for key derivation functions
title_full_unstemmed A robust security framework with bit-flipping attack and timing attack for key derivation functions
title_short A robust security framework with bit-flipping attack and timing attack for key derivation functions
title_sort robust security framework with bit-flipping attack and timing attack for key derivation functions
topic T175-178 Industrial research. Research and development
url http://eprints.uthm.edu.my/6534/1/AJ%202020%20%28331%29.pdf
http://eprints.uthm.edu.my/6534/
https://doi.org/10.1049/iet-ifs.2019.0163
url_provider http://eprints.uthm.edu.my/