A Formal Theory of Key Conjuring
Véronique Cortier, Stéphanie Delaune, Graham Steel · Proceedings - Computer Security Foundations Workshop/Proceedings · 2007
Key conjuring is the process by which an attacker obtains an unknown, encrypted key by repeatedly calling a cryptographic API function with random values in place of keys. We propose a formalism for detecting computationally feasible key conjuring operations, incorporated into a Dolev-Yao style model of the security API. We show that security in the presence of key conjuring operations is decidable for a particular class of APIs, which includes the key management API of IBM's common cryptographic architecture (CCA).