Reusing Static Keys in Key Agreement Protocols

  • Authors:
  • Sanjit Chatterjee;Alfred Menezes;Berkant Ustaoglu

  • Affiliations:
  • Department of Combinatorics & Optimization, University of Waterloo,;Department of Combinatorics & Optimization, University of Waterloo,;NTT Information Sharing Platform Laboratories, Tokyo, Japan

  • Venue:
  • INDOCRYPT '09 Proceedings of the 10th International Conference on Cryptology in India: Progress in Cryptology
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Contrary to conventional cryptographic wisdom, the NIST SP 800-56A standard explicitly allows the use of a static key pair in more than one of the key establishment protocols described in the standard. In this paper, we give examples of key establishment protocols that are individually secure, but which are insecure when static key pairs are reused in two of the protocols. We also propose an enhancement of the extended Canetti-Krawczyk security model and definition for the situation where static public keys are reused in two or more key agreement protocols.