How fast do you heal? A taxonomy for post-compromise security in secure-channel establishment

  • Olivier Blazy
  • , Ioana Boureanu
  • , Pascal Lafourcade
  • , Cristina Onete
  • , Léo Robert

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Post-Compromise Security (PCS) is a property of secure-channel establishment schemes, which limits the security breach of an adversary that has compromised one of the endpoint to a certain number of messages, after which the channel heals. An attractive property, especially in view of Snowden’s revelation of mass-surveillance, PCS was pioneered by the Signal messaging protocol, and is present in OTR. In this paper, we introduce a framework for quantifying and comparing PCS security, with respect to a broad taxonomy of adversaries. The generality and flexibility of our approach allows us to model the healing speed of a broad class of protocols, including Signal, but also an identity-based messaging protocol named SAID, and even a composition of 5G handover protocols.

Original languageEnglish
Title of host publication32nd USENIX Security Symposium, USENIX Security 2023
PublisherUSENIX Association
Pages5917-5934
Number of pages18
ISBN (Electronic)9781713879497
Publication statusPublished - 1 Jan 2023
Event32nd USENIX Security Symposium, USENIX Security 2023 - Anaheim, United States
Duration: 9 Aug 202311 Aug 2023

Publication series

Name32nd USENIX Security Symposium, USENIX Security 2023
Volume8

Conference

Conference32nd USENIX Security Symposium, USENIX Security 2023
Country/TerritoryUnited States
CityAnaheim
Period9/08/2311/08/23

Fingerprint

Dive into the research topics of 'How fast do you heal? A taxonomy for post-compromise security in secure-channel establishment'. Together they form a unique fingerprint.

Cite this