...
首页> 外文期刊>Journal of Cryptology >Beyond Conventional Security in Sponge-Based Authenticated Encryption Modes
【24h】

Beyond Conventional Security in Sponge-Based Authenticated Encryption Modes

机译:在基于海绵的身份验证加密模式下超越常规安全性

获取原文
获取原文并翻译 | 示例
           

摘要

The Sponge function is known to achieve 2c/2 security, where c is its capacity. This bound was carried over to its keyed variants, such as SpongeWrap, to achieve a min{2c/2,2 kappa} security bound, with kappa the key length. Similarly, many CAESAR competition submissions were designed to comply with the classical 2c/2 security bound. We show that Sponge-based constructions for authenticated encryption can achieve the significantly higher bound of min{2b/2,2c,2 kappa}, with bc the permutation size, by proving that the CAESAR submission NORX achieves this bound. The proof relies on rigorous computation of multi-collision probabilities, which may be of independent interest. We additionally derive a generic attack based on multi-collisions that matches the bound. We show how to apply the proof to five other Sponge-based CAESAR submissions: Ascon, CBEAM/STRIBOB, ICEPOLE, Keyak, and two out of the three PRIMATEs. A direct application of the result shows that the parameter choices of some of these submissions are overly conservative. Simple tweaks render the schemes considerably more efficient without sacrificing security. We finally consider the remaining one of the three PRIMATEs, APE, and derive a blockwise adaptive attack in the nonce-respecting setting with complexity 2c/2, therewith demonstrating that the techniques cannot be applied to APE.
机译:众所周知,海绵功能可实现2c / 2的安全性,其中c是其容量。该限制被延续到其键控变体(例如SpongeWrap),以实现最小{2c / 2,2 kappa}安全限制,且密钥长度为kappa。同样,许多CAESAR竞赛的参赛作品都设计为符合经典的2c / 2安全界限。通过证明CAESAR提交NORX达到了此界限,我们证明了用于身份验证加密的基于Sponge的构造可以实现min {2b / 2,2c,2 kappa}的更高界限,且b> c是排列大小。该证明依赖于对多碰撞概率的严格计算,这可能是独立引起关注的。我们还基于匹配边界的多冲突派生了一种通用攻击。我们展示了如何将证明应用于其他五种基于海绵的CAESAR提交文件:Ascon,CBEAM / STRIBOB,ICEPOLE,Keyak,以及三个PRIMATE中的两个。结果的直接应用表明,其中一些提交的参数选择过于保守。简单的调整使得该方案在不牺牲安全性的情况下更加有效。我们最终考虑了三个PRIMATE中的其余一个,即APE,并在复杂度为2c / 2的非随机数设置中派生了块状自适应攻击,这表明该技术无法应用于APE。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号