【24h】

Salvaging Weak Security Bounds for Blockcipher-Based Constructions

机译:拯救基于BlockCipher的结构的弱安全范围

获取原文

摘要

The concrete security bounds for some blockcipher-based constructions sometimes become worrisome or even vacuous; for example, when a light-weight blockcipher is used, when large amounts of data are processed, or when a large number of connections need to be kept secure. Rotating keys helps, but introduces a "hybrid factor" m equal to the number of keys used. In such instances, analysis in the ideal-cipher model (ICM) can give a sharper picture of security, but this heuristic is called into question when cryptanalysis of the real-world blockcipher reveals weak keys, related-key attacks, etc. To address both concerns, we introduce a new analysis model, the ideal-cipher model under key-oblivious access (ICM-KOA). Like the ICM, the ICM-KOA can give sharp security bounds when standard-model bounds do not. Unlike the ICM, results in the ICM-KOA are less brittle to current and future cryptanalytic results on the blockcipher used to instantiate the ideal cipher. Also, results in the ICM-KOA immediately imply results in the ICM and the standard model, giving multiple viewpoints on a construction with a single effort. The ICM-KOA provides a conceptual bridge between ideal ciphers and tweakable blockciphers (TBC): blockcipher-based constructions secure in the ICM-KOA have TBC-based analogs that are secure under standard-model TBC security assumptions. Finally, the ICM-KOA provides a natural framework for analyzing blockcipher key-update strategies that use the blockcipher to derive the new key. This is done, for example, in the NIST CTR-DRBG and in the hardware RNG that ships on Intel chips.
机译:一些基于块的结构的具体安全界有时会变得令人担忧或甚至是空缺;例如,当使用大量数据时,或者需要保持大量数据时,当需要保持安全时,或者需要保持安全。旋转键有助于,但引入“混合系数”M等于所使用的键数。在这种情况下,理想密码模型(ICM)中的分析可以给出安全性的安全性,但是当真实世界块密封的密码分析揭示弱钥匙,相关关键攻击等时,这种启发式被调用了问题既有问题,我们都介绍了一个新的分析模型,是关键令人沮丧的访问(ICM-KOA)下的理想密码模型。与ICM一样,ICM-KOA可以在标准模型界限时提供急剧的安全界限。与ICM不同,ICM-KOA的结果对于用于实例化理想密码的块密封块的当前和未来的密码结果不太脆。此外,ICM-KOA的结果立即意味着ICM和标准模型,在具有单一努力的建筑物上给出多个观点。 ICM-KOA提供理想的密码和调节块(TBC)之间的概念桥:基于BlockCipher的构造在ICM-KOA中的安全性具有基于TBC的类似物,该模拟在标准模型TBC安全假设下安全。最后,ICM-KOA提供了一种自然框架,用于分析使用BlockCial派生新密钥的BlockCipher键更新策略。这是在NIST CTR-DRBG中完成的,并且在Intel芯片上运送的硬件RNG。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号