Matches in SemOpenAlex for { <https://semopenalex.org/work/W84493089> ?p ?o ?g. }
- W84493089 abstract "Security critical applications often store keys on dedicated HSM or key-management servers to separate highly sensitive cryptographic operations from more vulnerable parts of the network. Access to such devices is given to protocol parties by the means of Security APIs, e.g., the RSA PKCS#11 standard, IBM's CCA and the TPM API, all of which protect keys by providing an API that allows to address keys only indirectly. This thesis has two parts. The first part deals with formal methods that allow for the identification of secure configurations in which Security APIs improve the security of existing protocols, e.g., in scenarios where parties can be corrupted. A promising paradigm is to regard the Security API as a participant in a protocol and then use traditional protocol analysis techniques. But, in contrast to network protocols, Security APIs often rely on the state of an internal database. When it comes to an analysis of an unbounded number of keys, this is the reason why current tools for protocol analysis do not work well. We make a case for the use of MSR as the back-end for verification and propose a new process calculus, which is a variant of the applied pi calculus with constructs for manipulation of a global state. We show that this language can be translated to MSR rules while preserving all security properties expressible in a dedicated first-order logic for security properties. The translation has been implemented in a prototype tool which uses the tamarin prover as a back-end. We apply the tool to several case studies among which a simplified fragment of PKCS#11, the Yubikey security token, and a contract signing protocol. The second part of this thesis aims at identifying security properties that a) can be established independent of the protocol, b) allow to catch flaws on the cryptographic level, and c) facilitate the analysis of protocols using the Security API. We adapt the more general approach to API security of Kremer et.al. to a framework that allows for composition in form of a universally composable key-management functionality. The novelty, compared to other definitions, is that this functionality is parametric in the operations the Security API allows, which is only possible due to universal composability. A Security API is secure if it implements correctly both key-management (according to our functionality) and all operations that depend on keys (with respect to the functionalities defining those operations). We present an implementation which is defined with respect to arbitrary functionalities (for the operations that are not concerned with key-management), and hence represents a general design pattern for Security APIs." @default.
- W84493089 created "2016-06-24" @default.
- W84493089 creator A5071250407 @default.
- W84493089 date "2014-01-07" @default.
- W84493089 modified "2023-09-26" @default.
- W84493089 title "Foundations for analyzing security APIs in the symbolic and computational model" @default.
- W84493089 cites W1414903598 @default.
- W84493089 cites W146244851 @default.
- W84493089 cites W1491991545 @default.
- W84493089 cites W1495832982 @default.
- W84493089 cites W1495938613 @default.
- W84493089 cites W1499934958 @default.
- W84493089 cites W1512043381 @default.
- W84493089 cites W1514302123 @default.
- W84493089 cites W1514304700 @default.
- W84493089 cites W1521419290 @default.
- W84493089 cites W1536580911 @default.
- W84493089 cites W1555053410 @default.
- W84493089 cites W1559498407 @default.
- W84493089 cites W1589756554 @default.
- W84493089 cites W1595155556 @default.
- W84493089 cites W1601458649 @default.
- W84493089 cites W1672755432 @default.
- W84493089 cites W171472358 @default.
- W84493089 cites W1721673008 @default.
- W84493089 cites W1775055752 @default.
- W84493089 cites W1863793285 @default.
- W84493089 cites W1912953170 @default.
- W84493089 cites W1973054120 @default.
- W84493089 cites W1996015920 @default.
- W84493089 cites W1997404185 @default.
- W84493089 cites W1997440650 @default.
- W84493089 cites W2002789557 @default.
- W84493089 cites W2006121619 @default.
- W84493089 cites W2022203768 @default.
- W84493089 cites W2029693536 @default.
- W84493089 cites W2030112111 @default.
- W84493089 cites W203757321 @default.
- W84493089 cites W2044073799 @default.
- W84493089 cites W2053014980 @default.
- W84493089 cites W2055259417 @default.
- W84493089 cites W2077836579 @default.
- W84493089 cites W2100683351 @default.
- W84493089 cites W2109266092 @default.
- W84493089 cites W2110712507 @default.
- W84493089 cites W2114189125 @default.
- W84493089 cites W2117064875 @default.
- W84493089 cites W2121845793 @default.
- W84493089 cites W2125030112 @default.
- W84493089 cites W2126272901 @default.
- W84493089 cites W2130459259 @default.
- W84493089 cites W2132477736 @default.
- W84493089 cites W2138889053 @default.
- W84493089 cites W2139017685 @default.
- W84493089 cites W2139172211 @default.
- W84493089 cites W2147201643 @default.
- W84493089 cites W2150426251 @default.
- W84493089 cites W2154554454 @default.
- W84493089 cites W2155032609 @default.
- W84493089 cites W2155222571 @default.
- W84493089 cites W2161544156 @default.
- W84493089 cites W2168537649 @default.
- W84493089 cites W2169819155 @default.
- W84493089 cites W2169908972 @default.
- W84493089 cites W2189299614 @default.
- W84493089 cites W2219132820 @default.
- W84493089 cites W2239388791 @default.
- W84493089 cites W2512132373 @default.
- W84493089 cites W2946824309 @default.
- W84493089 cites W3030059330 @default.
- W84493089 cites W3034345956 @default.
- W84493089 cites W3124439491 @default.
- W84493089 cites W4332981 @default.
- W84493089 cites W2482363909 @default.
- W84493089 cites W2612802984 @default.
- W84493089 cites W3149080678 @default.
- W84493089 hasPublicationYear "2014" @default.
- W84493089 type Work @default.
- W84493089 sameAs 84493089 @default.
- W84493089 citedByCount "0" @default.
- W84493089 crossrefType "dissertation" @default.
- W84493089 hasAuthorship W84493089A5071250407 @default.
- W84493089 hasConcept C108710211 @default.
- W84493089 hasConcept C121822524 @default.
- W84493089 hasConcept C142724271 @default.
- W84493089 hasConcept C159718280 @default.
- W84493089 hasConcept C171250308 @default.
- W84493089 hasConcept C178489894 @default.
- W84493089 hasConcept C192562407 @default.
- W84493089 hasConcept C199360897 @default.
- W84493089 hasConcept C204787440 @default.
- W84493089 hasConcept C2524010 @default.
- W84493089 hasConcept C2780385302 @default.
- W84493089 hasConcept C33884865 @default.
- W84493089 hasConcept C33923547 @default.
- W84493089 hasConcept C38652104 @default.
- W84493089 hasConcept C41008148 @default.
- W84493089 hasConcept C48103436 @default.
- W84493089 hasConcept C70388272 @default.
- W84493089 hasConcept C71924100 @default.