DocumentCode
1232523
Title
The Bare Bounded-Storage Model: The Tight Bound on the Storage Requirement for Key Agreement
Author
Dziembowski, Stefan ; Maurer, Ueli
Author_Institution
Univ. of Rome La Sapienza, Rome
Volume
54
Issue
6
fYear
2008
fDate
6/1/2008 12:00:00 AM
Firstpage
2790
Lastpage
2792
Abstract
In the bounded-storage model (BSM) for information-theoretic secure encryption and key agreement, one makes use of a random string whose length is greater than the assumed bound on the adversary Eve´s storage capacity. The legitimate parties, Alice and Bob, execute a protocol, over an authenticated channel accessible to Eve, to generate a secret key about which Eve has essentially no information even if she has infinite computing power. The string is either assumed to be accessible to all parties or communicated publicly from Alice to Bob. While in the BSM one often assumes that Alice and Bob initially share a short secret key, and the goal of the protocol is to generate a much longer key, in this communication, we consider the bare BSM without any initially shared secret key. It is proved that in the bare BSM, secret key agreement is impossible unless Alice and Bob have themselves very high storage capacity, namely, . This proves the optimality of a scheme proposed by Cachin and Maurer.
Keywords
cryptographic protocols; message authentication; authenticated channel; bounded-storage model; cryptographic protocol; information-theoretic secure encryption; random string; secret key agreement; storage requirement; Access protocols; Cryptography; Data mining; Information security; Power generation; Radio broadcasting; Satellite broadcasting; Secure storage; Bounded-storage model (BSM); cryptography; information-theoretic security; key agreement; lower bounds;
fLanguage
English
Journal_Title
Information Theory, IEEE Transactions on
Publisher
ieee
ISSN
0018-9448
Type
jour
DOI
10.1109/TIT.2008.921864
Filename
4529270
Link To Document