A Secure Key Management Interface with Asymmetric Cryptography

Marion Daubignard, David Lubicz, Graham Steel · 2013

Abstract. Cryptographic devices such as Hardware Security Modules are only as secure as their application programming interfaces (APIs) that offer cryp-tographic functionality to the outside world. Design flaws and implementation errors in security APIs have been shown to cause vulnerabilities that may leak secrets such as keys and PINs. Ideally, we would like to design such interfaces in such a way that we can formally prove security properties, even in the presence of some corrupted keys. In this work, we propose the first such provably secure interface to support asymmetric key operations for key management: Cachin and Chandran’s secure token interface supports asymmetric key operations only for encrypting and signing data, but not for managing keys, while Cortier and Steel handle only symmetric keys. Due to the fact that anyone can encrypt under a public key, in order to secure integrity of the keys under management, we must consider confidentiality and integrity properties separately and provide support for classical operations of public key infrastructure (e.g. certification of public keys). 1

Read the paper · More papers on PaperTik