Failsafe key escrow

Joe Kilian, T. Leighton · DSpace@MIT (Massachusetts Institute of Technology) · 1994

\Fair" Public Key Cryptosystems (FPKCs) have recently been proposed as a method for providing secure escrowing of keys without relying on special purpose hardware.In a fair public key cryptosystem, the cryptosystem users are allowed to choose their own public and private keys, but they must share their secret keys with a group of trustees (escrow agencies) in a manner that allows the trustees to reconstruct the secret key of any user in the event of a court order.The United States Government has recently acquired a license to Fair cryptosystem technology from Silvio Micali.The claimed advantage of the Micali FPKC o v er alternative approaches to key escrow is that the user in the Micali system is supposedly assured that his or her secret key will remain protected (unless the trustees collaborate to reconstruct the secret key), and the government is supposedly assured that criminals will not be able to abuse the escrow system in a manner that prevents government deciphering of wiretapped communications.In this paper, we expose a serious weakness in the Micali FPKC which allows criminals to abuse the system in precisely the manner which is not supposed to be possible.In particular, we show that the FPKC is subject to the sorts of subliminal key attacks discovered by Simmons and Desmedt in the 1980s [7, 1 7 , 1 8 , 19].As a consequence, we show h o w a g o v ernment-sanctioned FPKC a s e n visioned by Micali can be subverted by criminals to form a \shadow" public key cryptosystem that is untappable by the government.In some cases, the shadow cryptosystem is even more secure against the government than the original cryptosystem is against nongovernmental adversaries.Even if the shadow cryptosystem is run using only public knowledge and even if the government is fully aware of the workings of the shadow cryptosystem, there is no obvious way that the shadow system can be thwarted by the government.In the paper, we also describe a new approach t o k ey escrow that we call Failsafe Key Escrow.The Failsafe approach i s c haracterized by the use of government-user interaction to select the secret and public keys of each user.Failsafe key escrow has all the supposed advantages of Micali's FPKC, along with a formalizable guarantee that the system cannot be abused by criminals.The Failsafe method also guarantees the government that every user's secret key will be secure even if the user selects his or her portion of the secret key poorly (e.g., by using one's birthday instead of a random number).Finally, the method can be adapted for use with any of the commonly-cited cryptosystems, and it is particularly well suited for use in escrowing DSS keys.

Read the paper · More papers on PaperTik