计算机科学
后门
计算机安全
密码学
数字签名
密码原语
随机预言
Web服务
公钥密码术
加密
密码协议
万维网
散列函数
作者
Burong Kang,Lei Zhang,Yafang Yang,Xinyu Meng
标识
DOI:10.1007/978-3-031-22677-9_11
摘要
AbstractWeb services are service-oriented computing technology which allows computers running different operating domains to access and share each other’s databases. Each web service is an application (like online business) which may require the private information of users. Thus, it will be important to preserve these web users’ individual privacy. The traditional approaches to achieve this goal in web security is to use the cryptographic technologies, such as digital signature, NIZK proof system. Whereas, some recent research results indicate that these cryptographic technologies may suffer from the algorithm substitution attack (ASA). ASA means that the cryptographic technology would be embedded some backdoor in the process of its implementation by the attacker, and with the backdoor information the attacker can steal the user’s private information. To address this problem, the concept of cryptographic reverse firewall (CRF) has been introduced, which could sanitize the messages inputting and outputting the user’s computer. In this paper, we construct the CRFs for the efficient Pointcheval-Sanders (PS) signature as well as the NIZK proof system.KeywordsWeb securityCryptographic reverse firewallDigital signatureNon-interactive zero knowledge proof systemAlgorithm substitution attack
科研通智能强力驱动
Strongly Powered by AbleSci AI