TY - GEN
T1 - High-level cryptographic abstractions
AU - Kane, Christopher
AU - Lin, Bo
AU - Chand, Saksham
AU - Stoller, Scott D.
AU - Liu, Yanhong A.
N1 - Publisher Copyright:
© 2019 Association for Computing Machinery.
PY - 2019/11/15
Y1 - 2019/11/15
N2 - The interfaces exposed by commonly used cryptographic libraries are clumsy, complicated, and assume an understanding of cryptographic algorithms. The challenge is to design high-level abstractions that require minimum knowledge and effort to use while also allowing maximum control when needed. This paper proposes such high-level abstractions consisting of simple cryptographic primitives and full declarative configuration. These abstractions can be implemented on top of any cryptographic library in any language. We have implemented these abstractions in Python, and used them to write a wide variety of well-known security protocols, including Signal, Kerberos, and TLS. We show that programs using our abstractions are much smaller and easier to write than using low-level libraries, where size of security protocols implemented is reduced by about a third on average. We show our implementation incurs a small overhead, less than 5 microseconds for shared key operations and less than 341 microseconds (< 1%) for public key operations. We also show our abstractions are safe against main types of cryptographic misuse reported in the literature.
AB - The interfaces exposed by commonly used cryptographic libraries are clumsy, complicated, and assume an understanding of cryptographic algorithms. The challenge is to design high-level abstractions that require minimum knowledge and effort to use while also allowing maximum control when needed. This paper proposes such high-level abstractions consisting of simple cryptographic primitives and full declarative configuration. These abstractions can be implemented on top of any cryptographic library in any language. We have implemented these abstractions in Python, and used them to write a wide variety of well-known security protocols, including Signal, Kerberos, and TLS. We show that programs using our abstractions are much smaller and easier to write than using low-level libraries, where size of security protocols implemented is reduced by about a third on average. We show our implementation incurs a small overhead, less than 5 microseconds for shared key operations and less than 341 microseconds (< 1%) for public key operations. We also show our abstractions are safe against main types of cryptographic misuse reported in the literature.
KW - Cryptographic API
KW - Declarative configuration
KW - High-level abstraction
UR - https://www.scopus.com/pages/publications/85075891658
U2 - 10.1145/3338504.3357343
DO - 10.1145/3338504.3357343
M3 - Conference contribution
AN - SCOPUS:85075891658
T3 - Proceedings of the ACM Conference on Computer and Communications Security
SP - 31
EP - 43
BT - PLAS 2019 - Proceedings of the 14th ACM SIGSAC Workshop on Programming Languages and Analysis for Security
PB - Association for Computing Machinery
T2 - 14th ACM SIGSAC Workshop on Programming Languages and Analysis for Security, PLAS 2019, co-located with the 26th ACM Conference on Computer and Communications Security, ACM CCS 2019
Y2 - 15 November 2019
ER -