Beyond eCK: perfect forward secrecy under actor compromise and ephemeral-key reveal

Cas Cremers, Michèle Feltz
<span title="2013-07-12">2013</span> <i title="Springer Nature"> <a target="_blank" rel="noopener" href="" style="color: black;">Designs, Codes and Cryptography</a> </i> &nbsp;
We show that it is possible to achieve perfect forward secrecy in two-message or one-round key exchange (KE) protocols that satisfy even stronger security properties than provided by the extended Canetti-Krawczyk (eCK) security model. In particular, we consider perfect forward secrecy in the presence of adversaries that can reveal ephemeral secret keys and the long-term secret keys of the actor of a session (similar to Key Compromise Impersonation). We propose two new game-based security models
more &raquo; ... for KE protocols. First, we formalize a slightly stronger variant of the eCK security model that we call eCK w . Second, we integrate perfect forward secrecy into eCK w , which gives rise to the even stronger eCK-PFS model. We propose a security-strengthening transformation (i. e., a compiler ) between our new models. Given a two-message Diffie-Hellman type protocol secure in eCK w , our transformation yields a two-message protocol that is secure in eCK-PFS. As an example, we show how our transformation can be applied to the NAXOS protocol.
