پدافند الکترونیکی و سایبری

پدافند الکترونیکی و سایبری

بهبود امنیت شبکه گمنامی با استفاده از رمزنگاری QMNTR

نوع مقاله : مقاله پژوهشی

نویسندگان
1 دانشجوی کارشناسی ارشد،دانشگاه صنعتی ارومیه، ارومیه،ایران
2 استادیار،دانشگاه صنعتی ارومیه، ارومیه،ایران
چکیده
در بستر اینترنت و شبکه، تبادل امن داده‌ها به همراه گمنامی فرستنده و گیرنده یکی از نیازهای اصلی کاربران بوده است. ازاین‌رو، انواع شبکه‌های گمنامی طراحی و توسعه پیداکرده‌اند. معماری شبکه گمنامی و ضعف ساختاری سیستم رمزنگاری به‌کاررفته در آن‌ها باعث بروز مشکلات امنیتی متعددی شده است و با پیشرفت پردازش‌های کوانتومی، حملات متعددی طراحی و به‌طور موفقیت‌آمیزی امنیت شبکه گمنامی را مختل کرده است. سازوکارهای مختلفی برای بهبود امنیت شبکه‌های گمنامی ارائه‌شده است که برخی از آنان صرفاً جنبه نظری داشته و قابل پیاده‌سازی نبوده و برخی دیگر نیز دارای ضعف‌ها و آسیب‌پذیری‌های جدی هستند که قابلیت استفاده ندارند. شکسته شدن دستگاه‌های رمزنگاری، آسیب‌پذیر بودن امضاء‌های دیجیتال کلاسیک و الگوریتم‌های رمزنگاری غیر مقاوم در برابر حملات کوانتومی ازجمله ضعف‌های مهم معماری شبکه‌های گمنامی می‌باشند. برای غلبه بر این چالش‌ها، ساختاری امن با به‌کارگیری سیستم رمزنگاری QMNTR و امضاء دیجیتال LRS مبتنی بر ساختار مسیریابی پیازی، جهت امن سازی شبکه گمنامی پیشنهادشده است. نتایج بررسی‌ها‌ و ارزیابی فنی نشان می‌دهد ساختار معماری پیشنهادی توانایی مقابله با انواع تهدیدات را بهبود داده و باعث تضمین قابلیت اطمینان به رله‌ها در شبکه گمنامی شود. به‌علاوه، با پیچیدگی زمانی مناسب، امنیت توزیع کلید را افزایش و سربار ارتباط را کاهش داده است و با به‌کارگیری امضاء دیجیتال LRS، به ارتقای امنیت شبکه گمنامی کمک نموده است و کارایی قابل قبولی نیز دارد.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

Improving The Security of the Anonymous Network Using QMNTR Encryption

نویسندگان English

Mohammad Mahdi Daneshvar Jalayeri 1
PARVIZ RASHIDI KHAZAEE 2
1 Master's student, Urmia University of Technology, Urmia, Iran
2 Assistant Professor, Urmia University of Technology, Urmia, Iran
چکیده English

In the context of the Internet and network, secure data exchange along with the anonymity of sender and receiver has been one of the main needs of users. Therefore, various types of anonymity networks have been designed and developed. The architecture of the anonymity network and the structural weakness of the encryption system used in them have caused numerous security problems. with the advancement of quantum computing, many attacks have been designed and successfully disrupted the security of the anonymity network. Various mechanisms have been proposed to improve the security of anonymous networks, some of which are only theoretical and cannot be implemented, and others have serious weaknesses and vulnerabilities that cannot be used. The breaking of Encryption systems, the vulnerability of classic digital signatures, and non-resistant cryptographic algorithms against quantum attacks are among the important weaknesses of the architecture of anonymous networks. To overcome these challenges, a secure structure using a QMNTR encryption system and LRS digital signature based on the onion routing structure has been proposed to secure the anonymous network. The results of Research and technical evaluation show that the proposed architectural structure improves the ability to deal with all kinds of threats and ensures the reliability of relays in the anonymity network. In addition, with appropriate time complexity, the security of key distribution has increased and the communication overhead has been reduced. Using an LRS digital signature has also helped improve the anonymous network's security and has achieved acceptable performance.

کلیدواژه‌ها English

Anonymity Network Architecture
QMNTR encryption
LRS Digital Signature

Smiley face

 

[1]    Egners, André, et al. "Introducing SOR: SSH-based onion routing." 2012 26th International Conference on Advanced Information Networking and Applications Workshops.  (pp. 280-286) IEEE, 2012. https://doi.org/10.1109/WAINA.2012.89.
[2]    Bennett, Krista, and Christian Grothoff. "GAP–practical anonymous networking." International Workshop on Privacy Enhancing Technologies. Berlin, Heidelberg: Springer Berlin Heidelberg,     (pp. 141-160), 2003 .https://doi.org/10.1007/978-3-540-40956-4_10.
[3]    G. Danezis and C. Diaz, “A survey of anonymous communication channels,” Technical Report MSR-TR-2008-35, Microsoft Research, Tech. Rep., 2008. https://www.microsoft.com/en-us/research/wp-content/uploads/2008/02/tr-2008-35.pdf.
[4]    Karunanayake, Ishan, et al. "De-anonymisation attacks on tor: A survey." IEEE Communications Surveys & Tutorials 23.4 (2021): 2324-2350. https://doi.org/10.1109/COMST.2021.3093615.
[5]    A. Hasani Karbasi, "Designing Anonymous Communication System by Lattice-Based Cryptography”, Journal of Electronic & Cyber Defence Vol 2, No. 3, 2014. Available: https://sid.ir/paper/243126/en.
[6]    Yassein, Hassan R., Asia A. Abidalzahra, and Nadia M. Al-Saidi. "A new design of NTRU encryption with high security and performance level." AIP Conference Proceedings. Vol. 2334. No. 1. AIP Publishing LLC, 2021. doi.org/10.1063/5.0042312.
[7]    Ye, Qing, et al. "Efficient Linkable Ring Signature Scheme over NTRU Lattice with Unconditional Anonymity."Computational Intelligence and Neuroscience p.8431874 (2022). https://doi.org/10.1155/2022/8431874.
[8]    Shor, Peter W. "Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer." SIAM review 41.2 (1999): 303-332. https://doi.org/10.1137/S0036144598347011.
[9]    Rivest, Ronald L., Adi Shamir, and Leonard Adleman. "A method for obtaining digital signatures and public-key cryptosystems." Communications of the ACM 21.2 (1978):120-126. https://doi.org/10.1145/359340.359342.
[10]    Hoffstein, Jeffrey, Jill Pipher, and Joseph H. Silverman. "NTRU: A ring-based public key cryptosystem." International algorithmic number theory symposium. Berlin, Heidelberg: Springer Berlin Heidelberg, 1998.  pp. 267-288 https://doi.org/10.1007/BFb0054868.
[11]    Abo-Alsood, H. H., and H. R. Yassein. "QOTRU: A New Design of NTRU Public Key Encryption Via Qu-Octonion Subalgebra." Journal of Physics: Conference Series. Vol. 1999. No. 1. IOP Publishing, 2021. https://dx.doi.org/10.1088/1742-6596/1999/1/012097.
[13]    Wang, Tao, et al. "Congestion-aware path selection for Tor." Financial Cryptography and Data Security: 16th International Conference, FC 2012, Kralendijk, Bonaire, Februray 27-March 2, 2012, Revised Selected, Papers 16 98-113. Springer Berlin Heidelberg, 2012. doi.org/10.1007/978-3-642-32946-3_9.
[14]    The Tor Stack Exchenge,"Tor client pick Tor nodes for circuit creation," Retrieved from http://tor.stackexchange.com/questions/113/how-does-a-tor client-pick-tor-nodes-for-circuit-creation on July 21, 2018.
[15]    Jagerman, Rolf, et al. "The fifteen year struggle of decentralizing privacy-enhancing technology." arXiv preprint,arXiv:1404.4818 (2014). https://arxiv.org/abs/1404.4818.
[16]    Ahmad, Imran, et al. "A New Look at the TOR Anonymous Communication System." Journal of Digital Information Management 16.5 (2018): 223. https://doi.org/10.6025/jdim/2018/16/5/223-229.
[17]    Wang, Xiao, et al. "An empirical analysis of family in the Tor network." 2013 IEEE International Conference on Communications (ICC). IEEE, 2013.  (pp. 1995-2000). https://doi.org/10.1109/ICC.2013.6654817.
[19]    Z. Zhong, C. Xie and X. Tang, "Intrusion Traffic Detection and Classification Based on Unsupervised Learning," in IEEE Access, vol. 12, pp. 67860-67879, 2024, https://doi.org/10.1109/ACCESS.2024.3400213.
[20]    SPIEGEL Staff, Quantum Spying: GCHQ Used Fake LinkedIn Pages to Target Engineers‖, DER SPIEGEL, November 2013.
[21]    van Vredendaal, Christine. "Reduced memory meet-in-the-middle attack against the NTRU private key." LMS Journal of Computation and Mathematics 19.A (2016): 43-57. https://doi.org/10.1112/S1461157016000206.
[22]    Singh, Sonika, and Sahadeo Padhye. "Generalisations of NTRU cryptosystem." Security and Communication Networks 9.18 (2016): 6315-6334. https://doi.org/10.1002/sec.1693.
[23]    Goodin, D. "How the NSA might use Hotmail, Yahoo or other cookies to identify Tor users." Ars Technica (2013). http://arstechnica.com/security.
[24]    Zhu, Ye, et al. "Correlation-based traffic analysis attacks on anonymity networks." IEEE Transactions on Parallel and Distributed Systems 21.7 (2009): 954-967. https://doi.org/10.1109/TPDS.2009.146.
[25]    Dingledine, Roger, Nick Mathewson, and Paul F. Syverson. "Tor: The second-generation onion router." USENIX security symposium. Vol. 4. 2004. https://dl.acm.org/doi/10.5555/1251375.1251396.
[26]    Howgrave-Graham, Nick, et al. "The impact of decryption failures on the security of NTRU encryption." Annual International Cryptology Conference. Berlin, Heidelberg: Springer Berlin Heidelberg, 2003. https://doi.org/10.1007/978-3-540-45146-4_14.
[27]    Proos, John. "Imperfect decryption and an attack on the NTRU encryption scheme." Cryptology ePrint Archive (2003). https://ia.ca/2003/002.
[28]    Nitaj, Abderrahmane. "Cryptanalysis of NTRU with two public keys." Cryptology ePrint Archive (2011). https://doi.org/10.1109/ISEASP.2017.7976980.
[29]    Shim, Kyung-Ah. "Security vulnerabilities of four signature schemes from NTRU lattices and pairings." IEEE Access 8 (2020): 85019-85026. https://doi.org/10.1109/ACCESS.2020.2990413.
[30]    Xu, Liqing, et al. "Vulnerable Public Keys in NTRU Cryptosystem." Chinese Annals of Mathematics, Series B 41.5 (2020): 657-664. https://doi.org/10.1007/s11401-020-0225-6.
[31]    Yadav, Vijay Kumar, S. Venkatesan, and Shekhar Verma. "Man in the middle attack on NTRU key exchange." Communication, Networks and Computing: First International Conference, CNC 2018, Gwalior, India, March 22-24, 2018, Revised Selected Papers 1. Springer Singapore, 2019. https://doi.org/10.1007/978-981-13-2372-0_2.
[32]    S. Khoshnevisan, K. manochehri ― "New Method Base on MITM Attack on NTRU Encryption system", Research in Science and Technology - Istanbul-Turkey 14 March 2016 (in Persion). Available: https://sid.ir/paper/858473/fa.
[33]    Howgrave-Graham, Nick. "A hybrid lattice-reduction and meet-in-the-middle attack against NTRU." Advances in Cryptology-CRYPTO 2007: 27th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 19-23, 2007. Proceedings 27. Springer Berlin Heidelberg, (pp. 150-169) 2007. https://doi.org/10.1007/978-3-540-74143-5_9.
[34]    Ding, Jintai, Yanbin Pan, and Yingpu Deng. "An algebraic broadcast attack against NTRU." Information Security and Privacy: 17th Australasian Conference, ACISP 2012, Wollongong, NSW, Australia, July 9-11, 2012. Proceedings 17. Springer Berlin Heidelberg, 2012. http://dx.doi.org/10.1007/978-3-642-31448-3_10.
[35]    Adamoudis, Marios, and Konstantinos A. Draziotis. "Message recovery attack to NTRU using a lattice independent from the public key." arXiv preprint arXiv:2203.09620 (2022). https://doi.org/10.48550/arXiv.2203.09620.
[36]    Dingledine, Roger, and Steven J. Murdoch. "Performance Improvements on Tor or, Why Tor is slow and what we’re going to do about it." Online: http://www.torproject.org/press/presskit/2009-03-11-performance.pdf  (2009): 68.
[37]    AlSabah, Mashael, and Ian Goldberg. "PCTCP: per-circuit TCP-over-IPsec transport for anonymous communication overlay networks." Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security. 2013. https://doi.org/10.1145/2508859.2516715.
[38]    Tor Metrics Project website, "Tor project Anonimity online," Available at https://metrics.torproject.org.
[39]    Xu, Liqing, et al. "Vulnerable Public Keys in NTRU Cryptosystem." Chinese Annals of Mathematics, Series B 41.5 (2020): 657-664. https://doi.org/10.1007/s11401-020-0225-6.
[41]    Malekian, Ehsan, Ali Zakerolhosseini, and Atefeh Mashatan. "QTRU: a lattice attack resistant version of NTRU PKCS based on quaternion algebra." preprint, Available from the Cryptology ePrint Archive: http://eprint.iacr.org/2009/386.pdf (2009).
[42]    Malekian, Ehsan, and Ali Zakerolhosseini. "OTRU: A non-associative and high speed public key cryptosystem." 2010 15th CSI international symposium on computer architecture and digital systems. IEEE, pp. 83-90. 2010. https://doi.org/10.1109/CADS.2010.5623536.
[43]    Abdulwahhab, Saba Alaa, Qasim Mohammed Hussein, and Imad Fakhri Al-Shaikhli. "An overview of number theory research unit variant development security." Indonesian Journal of Electrical Engineering and Computer Science 28.2 (2022): 1164-1173. http://doi.org/10.11591/ijeecs.v28.i2.pp1164-1173.
[44]    J. K. Liu, M. H. Au, W. Susilo, and J. Zhou, “Linkable ring signature with unconditional anonymity,” IEEE Transactions on Knowledge and Data Engineering, vol. 26, no. 1, pp. 157– 165, 2013. https://doi.org/10.1109/TKDE.2013.17.
[45]    Wang, Shangping, Ru Zhao, and Yaling Zhang. "Lattice-based ring signature scheme under the random oracle model." International Journal of High Performance Computing and Networking 11.4 (2018): 332-341. https://doi.org/10.1504/IJHPCN.2018.093236.
[46]    Zhang, Huang, et al. "Anonymous post-quantum cryptocash." International Conference on Financial Cryptography and Data Security. Berlin, Heidelberg: Springer Berlin Heidelberg, 2018. https://doi.org/10.1007/978-3-662-58387-6_25.
[47]    Beullens, Ward, Shuichi Katsumata, and Federico Pintore. "Calamari and Falafl: logarithmic (linkable) ring signatures from isogenies and lattices." International Conference on the Theory and Application of Cryptology and Information Security. Cham: Springer International Publishing, 2020. https://doi.org/10.1007/978-3-030-64834-3_16.
[48]    Pohlig, Stephen, and Martin Hellman. "An improved algorithm for computing logarithms over GF (p) and its cryptographic significance (corresp.)." IEEE Transactions on information Theory 24.1 (1978): 106-110. https://doi.org/10.1109/TIT.1978.1055817.
[49]    Escribano Pablos, José Ignacio, and María Isabel González Vasco. "Secure post‐quantum group key exchange: Implementing a solution based on Kyber." IET Communications 17.6 (2023): 758-773. https://doi.org/10.1049/cmu2.12561.
[50]    W. Li et al., “High-rate quantum key distribution exceeding 110 Mb s−1,” Nat. Photon., vol. 17, no. 5, pp. 416–421, May 2023 https://doi.org/10.1038/s41566-023-01166-4.
[51]    Murdoch, Steven J. "Quantifying and measuring anonymity." International Workshop on Data Privacy Management. Berlin, Heidelberg: Springer Berlin Heidelberg, 2013. https://doi.org/10.1007/978-3-642-54568-9_1.
[52]    Diaz, Claudia, et al. "Towards measuring anonymity." International Workshop on Privacy Enhancing Technologies. Berlin, Heidelberg: Springer Berlin Heidelberg, 2002. https://doi.org/10.1007/3-540-36467-6_5.
[53]    Hoffstein, Jeffrey, et al. "NTRUSIGN: Digital signatures using the NTRU lattice." Cryptographers’ track at the RSA conference. Berlin, Heidelberg: Springer Berlin Heidelberg, 2003. https://doi.org/10.1007/3-540-36563-X_9.
[54]    Odoom, Justice, et al. "Linked or unlinked: A systematic review of linkable ring signature schemes." Journal of Systems Architecture 134 (2023): 102786. https://doi.org/10.1016/j.sysarc.2022.102786.
[55]    Cao,  Chengtang,  Lin  You,   and   Gengran    Hu. "A Novel Linkable Ring Signature on Ideal Lattices." Entropy 25.2 (2023): 237. https://doi.org/10.3390/e25020237.
[56]    Aguilar Melchor, Carlos, et al. "Adapting Lyubashevsky’s signature schemes to the ring signature setting." Progress in Cryptology–AFRICACRYPT 2013: 6th International Conference on Cryptology in Africa, Cairo, Egypt, June 22-24, 2013. Proceedings 6. Springer Berlin Heidelberg, 2013. https://doi.org/10.1007/978-3-642-38553-7_1.
[57]    Gao, Wen, et al. "Lattice-based deniable ring signatures." International Journal of Information Security 18 (2019): 355-370. https://doi.org/10.1007/s10207-018-0417-1.
[58]    Liu, Joseph K., Victor K. Wei, and Duncan S. Wong. "Linkable spontaneous anonymous group signature for ad hoc groups." Information Security and Privacy: 9th Australasian Conference, ACISP 2004, Sydney, Australia, July 13-15, 2004. Proceedings 9. Springer Berlin Heidelberg, (pp. 325-335) ,2004.     https://doi.org/10.1007/978-3-540-27800-9_28.
[59]    Farhad Fathi, "Discovering and Blocking Botnets Command and Control Channels in the Anonymous Network with Onion Routing (TOR) ", Master. Thesis,  Electrical and Computer Engineering, Tarbiat Modares University, October, 2019.
[60]    Ling, Zhen, et al. "Torward: Discovery, blocking, and traceback of malicious traffic over tor." IEEE Transactions on Information Forensics and Security 10.12 (2015): 2515-2530. https://doi.org/10.1109/TIFS.2015.2465934.
[61]    Deng, Ziye, et al. "Identifying tor anonymous traffic based on gravitational clustering analysis." 2017 9th International Conference on Intelligent Human-Machine Systems and Cybernetics (IHMSC). Vol. 2. IEEE, 2017. https://doi.org/10.1109/IHMSC.2017.133.
[62]    Elgzil, Abdelhamid, et al. "Cyber anonymity based on software-defined networking and Onion Routing (SOR)." 2017 IEEE conference on dependable and secure computing.  pp. 358-365 , IEEE, 2017. https://doi.org/10.1109/DESEC.2017.8073856.
[63]    Kita, Kentaro, et al. "Producer anonymity based on onion routing in named data networking." IEEE Transactions on Network and Service Management 18.2 (2020): 2420-2436. https://doi.org/10.1109/TNSM.2020.3019052.
[64]    Ghosh, Satrajit, and Aniket Kate. "Post-Quantum Forward-Secure Onion Routing: (Future Anonymity in Today’s Budget)." International Conference on Applied Cryptography and Network Security. Cham: Springer International Publishing, pp.263-286, 2015. https://doi.org/10.1007/978-3-319-28166-7_13.
[65]    Yang, Lei, and Fengjun Li. "mTor: A multipath Tor routing beyond bandwidth throttling." 2015 IEEE Conference on Communications and Network Security (CNS). IEEE,  pp. 479-487 2015. https://doi.org/10.1109/CNS.2015.7346860.
[66]    AlSabah, Mashael, et al. "The path less travelled: Overcoming Tor’s bottlenecks with traffic splitting." Privacy Enhancing Technologies: 13th International Symposium, PETS 2013, Bloomington, IN, USA, July 10-12, 2013. Proceedings 13. Springer Berlin Heidelberg, pp. 143-163, 2013. https://doi.org/10.1007/978-3-642-39077-7_8.
 
دوره 13، شماره 3 - شماره پیاپی 51
پاییز
پاییز 1404
صفحه 17-40

  • تاریخ دریافت 09 تیر 1404
  • تاریخ بازنگری 13 مرداد 1404
  • تاریخ پذیرش 18 شهریور 1404
  • تاریخ انتشار 01 آبان 1404