首页> 外文会议>Fast software encryption >Constructing Rate-1 MACs from Related-Key Unpredictable Block Ciphers: PGV Model Revisited
【24h】

Constructing Rate-1 MACs from Related-Key Unpredictable Block Ciphers: PGV Model Revisited

机译:从相关密钥不可预测的分组密码构造Rate-1 MAC:PGV模型

获取原文
获取原文并翻译 | 示例

摘要

Almost all current block-cipher-based MACs reduce their security to the pseudorandomness of their underlying block ciphers, except for a few of them to the unpredictability, a strictly weaker security notion than pseudorandomness. However, the latter MACs offer relatively low efficiency. In this paper, we investigate the feasibility of constructing rate-1 MACs from related-key unpredictable block ciphers. First, we show all the existing rate-1 MACs are insecure when instantiated with a special kind of related-key unpredictable block cipher. The attacks on them inspire us to propose an assumption that all the chaining values are available to adversaries for theoretically analyzing such MACs. Under this assumption, we study the security of 64 rate-1 MACs in keyed PGV model, and find that 1) 15 MACs are meaningless; 2) 25 MACs are vulnerable to three kinds of attacks respectively and 3) 24 MACs are provably secure when their underlying block ciphers are related-key unpredictable. Furthermore, we refine these 24 provably secure rate-1 MACs in Compact PGV model by removing a useless parameter away, and find that the resulting 6 provably secure MACs are in fact equivalent to each other. In the aspect of efficiency, however, the low rate of these secure MACs does not necessarily mean they can run faster than none rate-1 one MACs, due to their large number of key schedules.
机译:几乎所有当前基于块密码的MAC都将其安全性降低到其基础块密码的伪随机性,除了其中的少数几个具有不可预测性(严格来说,安全性要比伪随机性弱)。但是,后者的MAC效率相对较低。在本文中,我们研究了从相关密钥不可预测的分组密码构造速率为1的MAC的可行性。首先,我们显示了使用特殊类型的相关密钥不可预测的块密码实例化时,所有现有的速率1 MAC是不安全的。对它们的攻击促使我们提出一个假设,即所有链值都可用于对手以从理论上分析此类MAC。在此假设下,我们研究了密钥PGV模型中64个速率为1的MAC的安全性,发现1)15个MAC没有意义; 2)25个MAC分别容易受到三种攻击,并且3)当24个MAC的底层分组密码是不可预测的相关密钥时,证明它们是安全的。此外,我们通过删除无用的参数来精简Compact PGV模型中的这24个可证明安全的速率为1的MAC,并发现生成的6个可证明安全的MAC实际上彼此相等。但是,在效率方面,这些安全MAC的低速率并不一定意味着它们的密钥调度数量众多,因此它们的运行速度比没有速率的1个MAC更快。

著录项

  • 来源
    《Fast software encryption》|2010年|p.250-269|共20页
  • 会议地点 Seoul(KR);Seoul(KR)
  • 作者单位

    State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing 100190, P.R. China Graduate University of Chinese Academy of Sciences, Beijing 100049, P.R. China;

    State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing 100190, P.R. China Graduate University of Chinese Academy of Sciences, Beijing 100049, P.R. China;

    State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing 100190, P.R. China Graduate University of Chinese Academy of Sciences, Beijing 100049, P.R. China;

    State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing 100190, P.R. China Graduate University of Chinese Academy of Sciences, Beijing 100049, P.R. China;

    State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing 100190, P.R. China Graduate University of Chinese Academy of Sciences, Beijing 100049, P.R. China;

    State Key Laboratory of Information Security Institute of Software, Chinese Academy of Sciences, Beijing 100190, P.R. China Graduate University of Chinese Academy of Sciences, Beijing 100049, P.R. China;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 计算机软件;
  • 关键词

    message authentication code; block cipher; mode of operation; provable security;

    机译:消息认证码;分组密码操作模式;可证明的安全性;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号