大会名称
2010年 情報科学技術フォーラム(FIT)
大会コ-ド
F
開催年
2010
発行日
2010/8/20
セッション番号
1U
セッション名
暗号解析・解読
講演日
2010/09/07
講演場所(会議室等)
U会場(ウエスト2号館3F 302講義室)
講演番号
L-019
タイトル
A Keyed-Hashing Chain Scheme and its Security Analysis against Timing Attack
著者名
田村 仁
キーワード
Hashing Chain Scheme, Keyed-Hashing Chain Scheme, Second Pre-Image Attack, Timing Attack, Database Management System
抄録
Recently, a number of serious and realistic draw back of Database Management System, called timing vulnerability, are reported. The malicious users such as spammers can learn whether or not the user-data are comprised in database, using a timing attack. At this moment, the most popular countermeasure is unifying the time distance between HTTP requests and their responses. However, the time distance must be made consistent with the worst case. This raises a new problem for time efficiency. Whereas, if we simply substitute keyed-hashing for hashing at the chain scheme, it seems not only efficient but also secure against the timing attack. In this paper, we define the security of data-structure against timing attack, and evaluate the keyed-hashing chain scheme.
本文pdf
PDF download (113.8KB)