- Main
CONCISE: An Efficient and Resilient Alternative to Key Distribution for the Security of Computer Networks
Abstract
CONCISE (Cryptosystem for Obfuscation, Non-repudiation and Confidentiality with Integer Set Entanglements) is introduced as an alternative to existing key-distribution methods for the security of computer networks. CONCISE eliminates the need for deploying large numbers of symmetric keys, carrying out cryptographic handshakes, or having to trust third parties that authenticate public keys or distribute keys. Trusted nodes (e.g., routers in an OSPF or EIGRP network) are configured with their own identifiers and the same two secret integers shared by all trusted nodes of a network, which avoids misconfiguration errors associated with complex deployments of secrets. From such limited data any two trusted nodes can become cryptographically entangled in the use of encryption keys. CONCISE can be used with any symmetric-key cipher, including well-known ciphers like the Advanced Encryption Standard (AES) block cipher. It is shown that CONCISE provides very strong security against known attacks, and the performance results of implementations of known ciphers show that CONCISE can be used with any known cipher to provide an efficient approach to secure computer networks.
Many UC-authored scholarly publications are freely available on this site because of the UC's open access policies. Let us know how this access is important for you.