Invisible Adaptive Attacks.
Jesper Buus Nielsen, Mario Strefler · 2014
Abstract. We introduce the concept of an invisible adaptive attack (IAA) against cryptographic protocols. Or rather, it is a class of attacks, where the protocol itself is the attack, and where this cannot be seen by the security model. As an example, assume that we have some cryptographic security model M and assume that we have a current setting of the real world with some crypto-graphic infrastructure in place, like a PKI. Select some object from this real world infrastructure, like the public key, pk0, of some root certificate authority (CA). Now design a protocol pi, which is secure in M. Then massage it into p̂i, which runs exactly like pi, except that if the public key pk of the root CA happens to be pk0, then it will be completely insecure. Of course p̂i should be considered insecure. However, in current security models existing infrastructure is modelled by generating it at random in the experiment defining security. Therefore, in the model, the root CA will have a fresh, random public key pk. Hence pk 6 = pk0, except with negligible probability, and thus M will typically deem p̂i secure. The problem is that to notice the above attack in a security model, we need to properly model the correlation between p̂i and pk. However, this correlation was made by the adversary and it is näıve to believe that he will report this correlation correctly to the security model. It is the protocol itself and how to model it which is the attack. Furthermore, since