The Secure Channel

Niels Ferguson, Bruce Schneier, Tadayoshi Kohno · 2015

The secure channel is probably the most common of all practical problems. To implement a secure channel, we need a shared secret. This chapter discusses the security properties of the channel. The main argument for encrypt-and-authenticate is that the encryption and authentication processes can happen in parallel. The chapter formulates the security properties of the channel authenticates first for the rest of this chapter. The solution consists of three components: message numbering, authentication, and encryption. The chapter walks through the design of one possible secure channel and, in the process, illustrates how to think about the underlying issues. With judicious choice of the underlying MAC and the underlying encryption scheme, and by including additional data like the nonce in the input to the MAC, the encrypt-and-authenticate approach can be secure. The chapter also talks about the details of the secure channel and alternatives.

Read the paper · More papers on PaperTik