首页> 外文会议>International workshop on fast software encryption >Strengthening the Known-Key Security Notion for Block Ciphers
【24h】

Strengthening the Known-Key Security Notion for Block Ciphers

机译:加强分组密码的已知密钥安全性概念

获取原文
获取外文期刊封面目录资料

摘要

We reconsider the formalization of known-key attacks against ideal primitive-based block ciphers. This was previously tackled by Andreeva, Bogdanov, and Mennink (FSE 2013), who introduced the notion of known-key indifferentiability. Our starting point is the observation, previously made by Cogliati and Seurin (EUROCRYPT 2015), that this notion, which considers only a single known key available to the attacker, is too weak in some settings to fully capture what one might expect from a block cipher informally deemed resistant to known-key attacks. Hence, we introduce a stronger variant of known-key indifferentiability, where the adversary is given multiple known keys to 'play' with, the informal goal being that the block cipher construction must behave as an independent random permutation for each of these known keys. Our main result is that the 9-round iterated Even-Mansour construction (with the trivial key-schedule, i.e., the same round key xored between permutations) achieves our new 'multiple' known-keys indifferentiability notion, which contrasts with the previous result of Andreeva et al. that one single round is sufficient when only a single known key is considered. We also show that the 3-round iterated Even-Mansour construction achieves the weaker notion of multiple known-keys sequential indifferentiability, which implies in particular that it is correlation intractable with respect to relations involving any (polynomial) number of known keys.
机译:我们重新考虑针对理想的基于基元的分组密码的已知密钥攻击的形式。以前由Andreeva,Bogdanov和Mennink(FSE 2013)解决了这些问题,他们引入了已知密钥不可区分性的概念。我们的出发点是Cogliati和Seurin先前所做的观察(EUROCRYPT 2015),该概念仅考虑攻击者可用的单个已知密钥,在某些情况下太弱了以至于无法完全捕获一个区块可能期望的内容。非正式地认为是对已知密钥攻击具有抵抗力的密码。因此,我们引入了一个已知密钥不可区分性的更强变体,其中为对手提供了多个已知密钥以供“玩耍”,非正式的目标是,对于每个已知密钥,分组密码构造必须表现为独立的随机排列。我们的主要结果是,经过9轮迭代的Even-Mansour构造(具有琐碎的密钥调度,即在置换之间异或相同的圆形密钥)实现了我们新的“多个”已知密钥不可区分性概念,这与之前的结果形成了鲜明的对比。 Andreeva等人的文章。当只考虑一个已知密钥时,单回合就足够了。我们还表明,三轮迭代的Even-Mansour构造实现了多个已知密钥顺序不可微性的较弱概念,这尤其意味着,对于涉及任何(多项式)已知密钥的关系而言,它都是难解的相关性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号