Papers
Topics
Authors
Recent
Search
2000 character limit reached

Integrity-protecting block cipher modes -- Untangling a tangled web

Published 6 Mar 2024 in cs.CR | (2403.03654v2)

Abstract: This paper re-examines the security of three related block cipher modes of operation designed to provide authenticated encryption. These modes, known as PES-PCBC, IOBC and EPBC, were all proposed in the mid-1990s. However, analyses of security of the latter two modes were published more recently. In each case one or more papers describing security issues with the schemes were eventually published, although a flaw in one of these analyses (of EPBC) was subsequently discovered - this means that until now EPBC had no known major issues. This paper establishes that, despite this, all three schemes possess defects which should prevent their use - especially as there are a number of efficient alternative schemes possessing proofs of security.

Authors (1)
Definition Search Book Streamline Icon: https://streamlinehq.com
References (16)
  1. Breaking the IOC authenticated encryption mode. In D. Pointcheval and D. Vergnaud, editors, Progress in Cryptology — AFRICACRYPT 2014 — 7th International Conference on Cryptology in Africa, Marrakesh, Morocco, May 28–30, 2014. Proceedings, volume 8469 of Lecture Notes in Computer Science, pages 126–135. Springer, 2014.
  2. Correcting flaws in Mitchell’s analysis of EPBC. In I. Welch and X. Yi, editors, 13th Australasian Information Security Conference, AISC 2015, Sydney, Australia, January 2015, volume 161 of CRPIT, pages 57–60. Australian Computer Society, 2015.
  3. J. T. Kohl. The use of encryption in Kerberos for network authentication. In G. Brassard, editor, Advances in Cryptology — CRYPTO ’89, 9th Annual International Cryptology Conference, Santa Barbara, California, USA, August 20–24, 1989, Proceedings, volume 435 of Lecture Notes in Computer Science, pages 35–43. Springer-Verlag, Berlin, 1990.
  4. A fundamental flaw in the ++AE authenticated encryption mode. J. Math. Cryptol., 12(1):37–42, 2018.
  5. Forgery attacks on ++AE authenticated encryption mode. In ACSW ’16: Proceedings of the Australasian Computer Science Week Multiconference, Canberra, Australia, February 2–5, 2016, pages 1–9. ACM, 2016.
  6. Handbook of Applied Cryptography. CRC Press, Boca Raton, 1997.
  7. C. J. Mitchell. Cryptanalysis of two variants of PCBC mode when used for message integrity. In C. Boyd and J. M. Gonzalez Nieto, editors, Information Security and Privacy, 10th Australasian Conference, ACISP 2005, Brisbane, Australia, July 4–6 2005, Proceedings, number 3574 in Lecture Notes in Computer Science, pages 560–571. Springer-Verlag, Berlin, 2005.
  8. C. J. Mitchell. Cryptanalysis of the EPBC authenticated encryption mode. In S. D. Galbraith, editor, Cryptography and Coding, 11th IMA International Conference, Cirencester, UK, December 18-20, 2007, Proceedings, volume 4887 of Lecture Notes in Computer Science, pages 118–128. Springer-Verlag, Berlin, 2007.
  9. C. J. Mitchell. Analysing the IOBC authenticated encryption mode. In C. Boyd and L. Simpson, editors, Information Security and Privacy — 18th Australasian Conference, ACISP 2013, Brisbane, Australia, July 1–3, 2013. Proceedings, volume 7959 of Lecture Notes in Computer Science, pages 1–12. Springer, 2013.
  10. F. Recacha. IOBC: Un nuevo modo de encadenamiento para cifrado en bloque. In Proceedings: IV Reunion Espanola de Criptologia, Valladolid, September 1996, pages 85–92, 1996.
  11. F. Recacha. IOC: The most lightweight authenticated encryption mode? Available at https://csrc.nist.rip/groups/ST/toolkit/BCM/documents/proposedmodes/ioc/ioc-spec.pdf, March 2013.
  12. F. Recacha. ++AE v1.0. Available at https://competitions.cr.yp.to/round1/aev10.pdf, March 2014.
  13. F. Recacha. ++AE v1.1. Available at https://competitions.cr.yp.to/round1/aev11.pdf, April 2014.
  14. F. Recacha. Input output chaining (IOC) AE mode revisited. Available at https://inputoutputblockchaining.blogspot.com/, January 2014.
  15. A. Zuquete and P. Guedes. Transparent authentication and confidentiality for stream sockets. IEEE Micro, 16(3):34–41, May/June 1996.
  16. A. Zuquete and P. Guedes. Efficient error-propagating block chaining. In M. Darnell, editor, Cryptography and Coding, 6th IMA International Conference, Cirencester, UK, December 17–19, 1997, Proceedings, number 1355 in Lecture Notes in Computer Science, pages 323–334. Springer-Verlag, Berlin, 1997.

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.