AI 中文总结
本研究设计了基于 CSIDH 的 MCSI 密钥交换协议,通过盲化临时元素实现隐式双向认证,经 C 和 Python 实现测试,证明其安全性归约为强并行问题,同时指出部分未证明的安全属性。
AI 中文摘要
我们介绍 MCSI,这是一种基于 CSIDH 类群作用设计的双消息密钥交换协议,其中各方基于双方静态密钥确定的值,使用认证加密密钥发送其临时公开元素。该设计提供隐式双向认证,向窃听者隐藏临时元素,且接收方可在一次标签检查后丢弃未认证消息,而非在群作用计算后丢弃,群作用计算的成本比前者高四个数量级。在分析方面,我们证明该协议完全正确,且在随机预言模型中证明了三个结论,均归约为强并行问题:会话密钥针对被动敌手的不可区分性、盲化临时元素的保密性以及盲化传输的完整性。所有结论均未使用决策群作用假设,而该假设对于非素判别式的类群作用不成立。我们还证明,盲化密钥不能来自其旨在建立的会话密钥。为实例化该设计,我们选择参数并证明用于椭圆曲线离散对数的素数不可用:对于 $p = 2^{521}-1$(NIST P-521 素数),该作用不存在可高效计算的生成元。在实践方面,我们构建并测试了该设计:我们分别用 C 和 Python 实现该协议,对两者进行交叉验证,并测量会话在域运算、时间和内存方面的开销;我们还审计了代码中依赖秘密的控制流:域运算和对称层未发现此类流,而群作用因构造会泄露密钥,且 370 个密钥中,有两个密钥的一范数相差 5,其时间差异达 200 个计时单位。最后,我们说明未证明的内容,包括临时密钥泄露下的安全性、盲化的前向保密性以及恒定时间执行。
英文摘要
We introduce MCSI, a two message key exchange we design over the CSIDH class group action, in which each party sends its ephemeral public element under an authenticated encryption keyed by the value the two static keys determine. The design gives implicit mutual authentication, hides the ephemeral element from an eavesdropper, and lets a recipient discard an unauthenticated message after one tag check rather than after an evaluation of the group action, which is four orders of magnitude more expensive. On the analytic side, we prove that our protocol is correct with zero error, and prove three statements in the random oracle model, all reducing to the strong parallelisation problem: indistinguishability of the session key against a passive adversary, confidentiality of the blinded ephemeral element, and integrity of the blinded transport. None uses the decisional group action assumption, which is false for class group actions of non-prime discriminant. We also show that a blinding key cannot come from the session secret it is meant to establish. To instantiate the design we select parameters and show that a prime chosen for elliptic curve discrete logarithms is unusable: for $p = 2^{521}-1$, the NIST P-521 prime, the action admits no efficiently evaluable generator. On the practical side, we build and test the design. We implement the protocol twice, in C and independently in Python, cross check the two, and measure what a session costs in field operations, time and memory. We also audit our code for secret dependent control flow: the field arithmetic and the symmetric layer show none, while the group action leaks the key by construction, and two hundred timings separate two keys whose one-norms differ by five out of 370. Finally, we state what we do not prove, among them security under ephemeral key reveal, forward secrecy of the blinding, and constant time execution.
Comments38 pages, 6 figures, 6 tables. Reference implementation included as ancillary files and at https://github.com/FurkanCifci/mcsi-key-exchange