Paper 2017/234

Automatically Detecting Compromised Secrets: Foundations, Design Principles, and Applications

Kevin Milner
Cas Cremers
Jiangshan Yu
Mark Ryan
Abstract

We develop foundations and several constructions for security protocols that can automatically detect, without false positives, if a secret (such as a key or password) has been compromised. Such constructions can be used, e.g., to automatically shut down compromised services, or to automatically revoke compromised secrets to minimize the effects of compromise. Our threat model includes malicious agents, (temporarily or permanently) compromised agents, and clones. Previous works have studied domain-specific partial solutions to this problem. For example, Google's Certificate Transparency aims to provide infrastructure to detect the compromise of a certificate authority's signing key, logs have been used for detecting endpoint compromise, and protocols have been proposed to detect cloned RFID/smart cards. Contrary to these existing approaches, for which the designs are interwoven with domain-specific considerations and which usually do not enable fully automatic response (i.e., they need human assessment), our approach shows where automatic action is possible. Our results unify, provide design rationales, and suggest improvements for the existing domain-specific solutions. Based on our analysis, we construct several mechanisms for the detection of compromised secrets. Our mechanisms enable automatic response, such as revoking keys or shutting down services, thereby substantially limiting the impact of a compromise. In several case studies, we show how our mechanisms can be used to substantially increase the security guarantees of a wide range of systems, such as web logins, payment systems, or electronic door locks. For example, we propose and formally verify an improved version of Cloudflare's Keyless SSL protocol that enables key compromise detection.

Note: Changelog in Appendix A.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. IEEE Computer Security Foundations Symposium (CSF) 2017
Contact author(s)
cremers @ cispa de
History
2026-01-21: last of 6 revisions
2017-03-11: received
See all versions
Short URL
https://ia.cr/2017/234
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2017/234,
      author = {Kevin Milner and Cas Cremers and Jiangshan Yu and Mark Ryan},
      title = {Automatically Detecting Compromised Secrets: Foundations, Design Principles, and Applications},
      howpublished = {Cryptology {ePrint} Archive, Paper 2017/234},
      year = {2017},
      url = {https://eprint.iacr.org/2017/234}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.