H2020Individual fellowship2017–2020

POMEGRANATE · Practice-Oriented Security Models and Granular Designs for Future-Proof Authenticated Encryption

Horizon 2020 — Marie Skłodowska-Curie Actions

Duration
2017-09-01 → 2020-08-30
EU contribution
€172,800
Participants
1
Scheme
MSCA-IF

Lines connect the coordinator with its partners.

Results in brief

Practice-Oriented Security Models and Granular Designs for Future-Proof Authenticated Encryption

Authenticated-Encryption (AE) algorithms are cryptographic tools for providing data confidentiality and integrity services simultaneously. AE algorithms are ubiquitous in protocols to secure the very fundamentals of the information and communication infrastructure, being adopted into widely deployed protocols, such as TLS, SSH, IPsec, IEEE 802.11 (Wi-Fi) and ANSI C12.22 (Smart Grid). A wide range of recently reported security vulnerabilities and exploits, arisen from either using insecure designs to achieve the AE goal or misusing supposedly secure AE schemes, motivated the cryptographic community to run the CAESAR competition for designing new AE algorithms, boosting research on AE. Yet a critical look at the classical security models for AE, defined over the last decade, that guided the constructions of CAESAR submissions, and a review of practical applications for AE algorithms reveals several inconsistencies and remaining problems that must be carefully investigated before moving towards adoption of next-generation AE schemes for widespread use in governmental, industrial and financial ICT systems. POMEGRANATE revisited the existing security models and robustness features for AE schemes and developed fine-grained security models and modular design paradigms that can flexibly capture a widening spectrum of disparate security and performance requirements in several emerging application environments such as Internet of Things (IoT), secure communication in Automotive system and 5G infrastructure. The project identified important ongoing challenges and provided solutions towards bridging the gaps between the theory and practice of AE in these important practical use cases. The results will also impact the development and evaluation of new lightweight AE algorithms in the ongoing international standardization projects; in particular NIST’s lightweight cryptography project and AUTOSAR standards for Automotive industry, as we have been actively contributing to these standardization activities.

Data: CORDIS, © European Union

Project objective

Authenticated-Encryption (AE) algorithms have recently faced an immense increase in popularity as appropriate cryptographic tools for providing data confidentiality and integrity services simultaneously. AE algorithms are ubiquitous in protocols to secure the very fundamentals of the information and communication infrastructure, being adopted into widely-deployed protocols, such as TLS, SSH, IPsec, IEEE 802.11 (Wi-Fi) and ANSI C12.22. A wide range of recently reported security vulnerabilities and exploits, arisen from either using insecure designs to achieve the AE goal or misusing supposedly secure AE schemes, has motivated the cryptographic community to run the CAESAR competition for designing new AE algorithms, boosting research on AE. Yet a critical look at the classical security models for AE, defined over the last decade, that guided the constructions of CAESAR submissions, and a review of practical applications for AE algorithms reveals several inconsistencies and remaining problems that must be carefully investigated before moving towards adoption of next-generation AE schemes for widespread use in governmental, industrial and financial ICT systems. POMEGRANATE aims to critically rethink the existing security notions and robustness features for AE schemes and to develop fine-grained security models and modular, future-proof design paradigms that can flexibly capture a widening spectrum of disparate requirements in the emerging streaming media applications such as IPTV as well as in future heterogeneous environments such as Internet of Things and Cloud Computing infrastructures. We aim to proactively identify important ongoing challenges and to bridge the gaps between the theory and practice of AE, looking far beyond the design-centric CAESAR competition. Nevertheless, the results will also impact the evaluation and ranking of the CAESAR finalists, as those schemes should offer a set of envisioned new security and robustness needs for future applications.

Original text from CORDIS.

Participants

  • KATHOLIEKE UNIVERSITEIT LEUVEN · LeuvenCoordinatorBelgium

Links

Data: CORDIS, © European Union