Sciweavers

ACISP
2008
Springer

Comparing the Pre- and Post-specified Peer Models for Key Agreement

14 years 6 months ago
Comparing the Pre- and Post-specified Peer Models for Key Agreement
In the pre-specified peer model for key agreement, it is assumed that a party knows the identifier of its intended communicating peer when it commences a protocol run. On the other hand, a party in the post-specified peer model for key agreement does not know the identifier of its communicating peer at the outset, but learns the identifier during the protocol run. In this paper we compare the security assurances provided by the Canetti-Krawczyk security definitions for key agreement in the pre- and post-specified peer models. We give examples of protocols that are secure in one model but insecure in the other. We also enhance the Canetti-Krawczyk security models and definitions to encompass a class of protocols that are executable and secure in both the pre- and post-specified peer models.
Alfred Menezes, Berkant Ustaoglu
Added 01 Jun 2010
Updated 01 Jun 2010
Type Conference
Year 2008
Where ACISP
Authors Alfred Menezes, Berkant Ustaoglu
Comments (0)