Certified computer-aided cryptography: Efficient provably secure machine code from high-level implementations

dc.contributor.author José Bacelar Almeida en
dc.contributor.author Manuel Barbosa en
dc.contributor.author Barthe,G en
dc.contributor.author Dupressoir,F en
dc.date.accessioned 2017-12-22T10:02:20Z
dc.date.available 2017-12-22T10:02:20Z
dc.date.issued 2013 en
dc.description.abstract We present a computer-aided framework for proving concrete security bounds for cryptographic machine code implementations. The front-end of the framework is an interactive verification tool that extends the EasyCrypt framework to reason about relational properties of C-like programs extended with idealised probabilistic operations in the style of code-based security proofs. The framework also incorporates an extension of the CompCert certified compiler to support trusted libraries providing complex arithmetic calculations or instantiating idealized components such as sampling operations. This certified compiler allows us to carry to executable code the security guarantees established at the high-level, and is also instrumented to detect when compilation may interfere with side-channel countermeasures deployed in source code. We demonstrate the applicability of the framework by applying it to the RSA-OAEP encryption scheme, as standardized in PKCS#1 v2.1. The outcome is a rigorous analysis of the advantage of an adversary to break the security of assembly implementations of the algorithms specified by the standard. The example also provides two contributions of independent interest: it bridges the gap between computer-assisted security proofs and real-world cryptographic implementations as described by standards such as PKCS,and demonstrates the use of the CompCert certified compiler in the context of cryptographic software development. © 2013 ACM. en
dc.identifier.uri http://repositorio.inesctec.pt/handle/123456789/4735
dc.identifier.uri http://dx.doi.org/10.1145/2508859.2516652 en
dc.language eng en
dc.relation 5604 en
dc.relation 5598 en
dc.rights info:eu-repo/semantics/openAccess en
dc.title Certified computer-aided cryptography: Efficient provably secure machine code from high-level implementations en
dc.type conferenceObject en
dc.type Publication en
Files
Original bundle
Now showing 1 - 1 of 1
Thumbnail Image
Name:
P-008-J03.pdf
Size:
471.72 KB
Format:
Adobe Portable Document Format
Description: