Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
|
 |
Security Analysis and Improvement of the Global Key Recovery System
| |
|
Security Analysis and Improvement of the Global Key Recovery System
Yanjiang Yang6 , Feng Bao6 and Robert H. Deng6 
| (6) |
Laboratories for Information Technology, 21 Heng Mui Keng Terrace, Singapore, 119613 |
Abstract
Key recovery is a technology that allows the owner of encrypted data or a trusted third party to recover encrypted data, mostly
by reconstructing lost decryption key. In [HLG99], Harn et al proposed a Global Key Recovery System (GKRS) that combines the functions of the key recovery authorities and the public key
certification authorities (CAs). Among other features, user-dominance, i.e., a user is allowed to select his own public-private
key pair and especially a public element for verifying the validity of the public-private key pair, is considered extremely
important by [HLG99] for wide acceptance of GKRS. In this paper, we attack the RSA version of GKRS by showing that its user-dominant feature
and the corresponding key verification scheme employed by the CAs allow for fraud by users against CAs. We then propose an
improvement to the original GKRS. The improved system makes the probability of user fraud negligibly small.
Fulltext Preview (Small, Large)
 References secured to subscribers.
|
|
|
|
|
|