Misplaced Pages

Sakai–Kasahara scheme

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.

The Sakai–Kasahara scheme, also known as the Sakai–Kasahara key encryption algorithm (SAKKE), is an identity-based encryption (IBE) system proposed by Ryuichi Sakai and Masao Kasahara in 2003. Alongside the Boneh–Franklin scheme, this is one of a small number of commercially implemented identity-based encryption schemes. It is an application of pairings over elliptic curves and finite fields. A security proof for the algorithm was produced in 2005 by Chen and Cheng. SAKKE is described in Internet Engineering Task Force (IETF) RFC 6508.

As a specific method for identity-based encryption, the primary use case is to allow anyone to encrypt a message to a user when the sender only knows the public identity (e.g. email address) of the user. In this way, this scheme removes the requirement for users to share public certificates for the purpose of encryption.

Description of scheme

The Sakai–Kasahara scheme allows the encryption of a message M {\displaystyle \mathbb {M} } to an receiver with a specific identity, I U {\displaystyle \textstyle I_{U}} . Only the entity with the private key, K U {\displaystyle \textstyle K_{U}} , associated to the identity, I U {\displaystyle \textstyle I_{U}} , will be capable of decrypting the message.

As part of the scheme, both the sender and receiver must trust a Private Key Generator (PKG), also known as a Key Management Server (KMS). The purpose of the PKG is to create the receiver's private key, K U {\displaystyle \textstyle K_{U}} , associated to the receiver's identity, I U {\displaystyle \textstyle I_{U}} . The PKG must securely deliver the identity-specific private key to the receiver, and PKG-specific public parameter, Z {\displaystyle \textstyle Z} , to all parties. These distribution processes are not considered as part of the definition of this cryptographic scheme.

Preliminaries

The scheme uses two multiplicative groups E {\displaystyle \textstyle E} and G {\displaystyle \textstyle G} . It is assumed:

  • The Diffie-Hellman problem is hard in E {\displaystyle \textstyle E} . Meaning that given two members of the group P {\displaystyle \textstyle P} and Q {\displaystyle \textstyle Q} , it is hard to find x {\displaystyle \textstyle x} such that [ x ] . P = Q {\displaystyle \textstyle .P=Q} .
  • The Diffie-Hellman problem is hard in G {\displaystyle \textstyle G} . Meaning that given two members of the group g {\displaystyle g} and t {\displaystyle t} , it is hard to find x {\displaystyle \textstyle x} such that g x = t {\displaystyle \textstyle g^{x}=t} .
  • There is a bilinear map, a Tate-Lichtenbaum pairing, e ( , ) {\displaystyle \textstyle e(,)} from E to G. This means that for P {\displaystyle \textstyle P} a member of E {\displaystyle \textstyle E} :
e ( P , [ x ] . P ) = e ( [ x ] . P , P ) = e ( P , P ) x {\displaystyle \textstyle e(P,.P)=e(.P,P)=e(P,P)^{x}}

Frequently, E {\displaystyle \textstyle E} is a supersingular elliptic curve, such as E : y 2 = x 3 3 x {\displaystyle \textstyle E:y^{2}=x^{3}-3x} (over a finite field of prime order p {\displaystyle \textstyle p} ). A generator P {\displaystyle \textstyle P} of prime order q {\displaystyle \textstyle q} is chosen in E {\displaystyle \textstyle E} . The group G {\displaystyle \textstyle G} is the image due to the pairing of the group generated by P {\displaystyle \textstyle P} (in the extension field of degree 2 of the finite field of order p).

Two hash functions are also required, H 1 {\displaystyle \textstyle H_{1}} and H 2 {\displaystyle \textstyle H_{2}} . H 1 {\displaystyle \textstyle H_{1}} outputs a positive integer, x {\displaystyle \textstyle x} , such that 1 < x < q {\displaystyle \textstyle 1<x<q} . H 2 {\displaystyle \textstyle H_{2}} outputs n {\displaystyle \textstyle n} bits, where n {\displaystyle \textstyle n} is the length of the message M {\displaystyle \mathbb {M} } .

Key generation

The PKG has a master secret z {\displaystyle \textstyle z} where 1 < z < q {\displaystyle 1<z<q} , and a public key Z = [ z ] . P {\displaystyle \textstyle Z=.P} which is a point on E {\displaystyle \textstyle E} . The PKG generates the private key, K U {\displaystyle \textstyle K_{U}} , for the user with identity I D U {\displaystyle \textstyle ID_{U}} as follows:

K U = [ 1 z + H 1 ( I D U ) ] . P {\displaystyle \textstyle K_{U}=.P}

Encryption

To encrypt a non-repeating message M {\displaystyle \mathbb {M} } , the sender requires receiver's identity, I D U {\displaystyle \textstyle ID_{U}} and the public PGK value Z {\displaystyle \textstyle Z} . The sender performs the following operation.

  1. Create: i d = H 1 ( I D U ) {\displaystyle \textstyle id=H_{1}(ID_{U})}
  2. The sender generates r {\displaystyle \textstyle r} using r = H 1 ( M | | i d ) {\displaystyle \textstyle r=H_{1}(\mathbb {M} ||id)}
  3. Generate the point R {\displaystyle \textstyle R} in E {\displaystyle \textstyle E} :
    R = [ r ] . ( [ i d ] . P + Z ) {\displaystyle \textstyle R=.(.P+Z)}
  4. Create the masked message:
    S = M H 2 ( g r ) {\displaystyle \textstyle S=\mathbb {M} \oplus H_{2}(g^{r})}
  5. The encrypted output is: ( R , S ) {\displaystyle \textstyle (R,S)}

Note that messages may not repeat, as a repeated message to the same identity results in a repeated ciphertext. There is an extension to the protocol should messages potentially repeat.

Decryption

To decrypt a message encrypted to I D U {\displaystyle \textstyle ID_{U}} , the receiver requires the private key, K U {\displaystyle \textstyle K_{U}} from the PKG and the public value Z {\displaystyle \textstyle Z} . The decryption procedure is as follows:

  1. Compute i d = H 1 ( I D U ) {\displaystyle \textstyle id=H_{1}(ID_{U})}
  2. Receive the encrypted message: ( R , S ) {\displaystyle \textstyle (R,S)} .
  3. Compute:
    w = e ( R , K U ) {\displaystyle \textstyle w=e(R,K_{U})}
  4. Extract the message:
    M = S H 2 ( w ) {\displaystyle \textstyle \mathbb {M} =S\oplus H_{2}(w)}
  5. To verify the message, compute r = H 1 ( M | | i d ) {\displaystyle \textstyle r=H_{1}(\mathbb {M} ||id)} , and only accept the message if:
    [ r ] . ( [ i d ] . P + Z ) R {\displaystyle \textstyle .(.P+Z)\equiv R}

Demonstration of algorithmic correctness

The following equations demonstrate the correctness of the algorithm:

w = e ( R , K U ) = e ( [ r ] . ( [ i d ] . P + Z ) , K U ) = e ( [ r ] . ( [ i d ] . P + [ z ] . P ) , K U ) = e ( [ r ( i d + z ) ] . P , K U ) {\displaystyle \textstyle w=e(R,K_{U})=e(.(.P+Z),K_{U})=e(.(.P+.P),K_{U})=e(.P,K_{U})}

By the bilinear property of the map:

w = e ( [ r ( i d + z ) ] . P , K U ) = e ( [ r ( i d + z ) ] . P , [ 1 ( i d + z ) ] . P ) = e ( P , P ) r ( i d + z ) ( i d + z ) = g r {\displaystyle \textstyle w=e(.P,K_{U})=e(.P,.P)=e(P,P)^{\frac {r(id+z)}{(id+z)}}=g^{r}}

As a result:

S H 2 ( w ) = ( M H 2 ( g r ) ) H 2 ( w ) = M {\displaystyle \textstyle S\oplus H_{2}(w)=(\mathbb {M} \oplus H_{2}(g^{r}))\oplus H_{2}(w)=\mathbb {M} }

Standardisation

There are four standards relating to this protocol:

  • Initial standardisation of scheme was begun by IEEE in 2006.
  • The scheme was standardised by the IETF in 2012 within RFC 6508.
  • A key-exchange algorithm based on the scheme is the MIKEY-SAKKE protocol developed by the UK's national intelligence and security agency, GCHQ, and defined in RFC 6509.
  • Sakai-Kasahara, as specified in MIKEY-SAKKE, is the core key-exchange algorithm of the Secure Chorus encrypted Voice over IP standard.

Security

In common with other identity-based encryption schemes, Sakai-Kasahara requires that the Key Management Server (KMS) stores a master secret from which all users' private keys can be generated. Steven Murdoch has criticised MIKEY-SAKKE for creating a security vulnerability through allowing the KMS to decrypt every users' communication. Murdoch also noted that the lack of forward secrecy in MIKEY-SAKKE increases the harm that could result from the master secret being compromised. GCHQ, the creator of MIKEY-SAKKE, disputed this analysis, pointing out that the some organisations may consider such monitoring capabilities to be desirable for investigative or regulatory reasons, and that the KMS should be protected by an air-gap.

Cryptographic libraries and implementations

The scheme is part of the MIRACL cryptographic library.

See also

References

  1. Sakai, Ryuichi; Kasahara, Masao (2003). "ID Based cryptosystems with pairing on elliptic curve" (PDF). Cryptography ePrint Archive. 2003/054.
  2. Chen, L.; Cheng, Z. "Security proof of Sakai-Kasahara's identity-based encryption scheme" (PDF). Cryptography ePrint Archive. 2005/226.
  3. Groves, M. (February 2012). Sakai-Kasahara Key Encryption (SAKKE). IETF. doi:10.17487/RFC6508. RFC 6508.
  4. Barbosa, M.; et al. (January 2006). "SK-KEM: An Identity-Based KEM [IEEE P1363.3 submission]".
  5. "Common Technology Standards". Secure Chorus. 2019. Archived from the original on 2020-02-04. Retrieved 4 February 2020.
  6. Murdoch, Steven J. (March 2016). "Insecure by Design: Protocols for Encrypted Phone Calls". Computer. 49 (3). IEEE: 25–33. doi:10.1109/MC.2016.70. S2CID 10072519.
  7. Murgia, Madhumita (22 January 2016). "GCHQ-developed software for secure phone calls open to 'eavesdropping'". The Telegraph. Archived from the original on 2019-07-09. Retrieved 2020-02-04.
  8. Baraniuk, Chris (23 January 2016). "GCHQ-developed phone security 'open to surveillance'". BBC News. Retrieved 2020-02-04.
  9. Levy, Ian (26 January 2016). "The development of MIKEY-SAKKE". GCHQ. Retrieved 2020-02-04.
  10. "MIKEY-SAKKE frequently asked questions". GCHQ. 7 August 2016. Retrieved 2020-02-04.
Categories: