The key to secure mobile signature: from password-based protection to two-party signatures
Abstract
Nowadays, the widespread deployment of cryptographic mechanisms is inextricably linked to the use of mobile devices. However, this introduces the problem of their relatively low level of security — both in organizational and technical-engineering aspects. This requires that hardware and software solutions provide protection not only within standard adversary models but also within extended ones, which assume that some of the basic security requirements for safe operation have been violated, resulting in the compromise of the device or the user’s password. This paper presents an analysis of the security of five common classes of solutions for electronic signature operations under several representative extended adversary models. Additionally, the study examines the necessity of establishing trust to an additional party involved in the interaction.
Full Text:
PDF (Russian)References
Aranha D., Novaes F., Takahashi A., Tibouchi M., Yarom Y. "LadderLeak: Breaking ECDSA with Less than One Bit of Nonce Leakage". CCS ’20: 2020 ACM SIGSAC Conference on Computer and Communications Security. pp. 225-242. 2020.
Fouque P.A., Tibouchi M., Zapalowicz J.C. (2013). "Recovering Private Keys Generated with Weak PRNGs". In: Stam, M. (eds) Cryptography and Coding. IMACC 2013. Lecture Notes in Computer Science, vol 8308. Springer, Berlin, Heidelberg.
Alekseev E.K., Nikiforova L.O. “Electronic Signature in the Context of Mass Adoption”, CTCrypt 2024, (in Russian).
Alekseev E.K., Akhmetzyanova L.R., Babueva A.A., Nikiforova L.O., Smyshlyaev S.V. “Two-party Signature Scheme of GOST”, Mathematical Aspects of Cryptography, 15:2 (2024), 7–28., (in Russian).
https://doi.org/10.4213/mvk467
Akhmetzyanova L.R., Alekseev E.K., Smyshlyaev S.V., Babueva A.A., Nikiforova L.O. “Two-party signature: how to sign securely using a mobile device”, AgileCrypto 2025, https://agilecrypto.biz/en
Lindell Y. "Fast Secure Two-Party ECDSA Signing". J Cryptol 34, 44 (2021).
Agafyin S.S., Smyshlyaev S.V. “Enhancing the Security of Access to Electronic Signature Keys in a Weakly Trusted Environment”, International Journal of Open Information Technologies, ISSN: 2307-8162, vol. 9, no. 1.
Refbacks
- There are currently no refbacks.
Abava Кибербезопасность ИТ конгресс СНЭ
ISSN: 2307-8162