Integrity-protecting block cipher modes -- Untangling a tangled web
Abstract: This paper re-examines the security of three related block cipher modes of operation designed to provide authenticated encryption. These modes, known as PES-PCBC, IOBC and EPBC, were all proposed in the mid-1990s. However, analyses of security of the latter two modes were published more recently. In each case one or more papers describing security issues with the schemes were eventually published, although a flaw in one of these analyses (of EPBC) was subsequently discovered - this means that until now EPBC had no known major issues. This paper establishes that, despite this, all three schemes possess defects which should prevent their use - especially as there are a number of efficient alternative schemes possessing proofs of security.
- Breaking the IOC authenticated encryption mode. In D. Pointcheval and D. Vergnaud, editors, Progress in Cryptology — AFRICACRYPT 2014 — 7th International Conference on Cryptology in Africa, Marrakesh, Morocco, May 28–30, 2014. Proceedings, volume 8469 of Lecture Notes in Computer Science, pages 126–135. Springer, 2014.
- Correcting flaws in Mitchell’s analysis of EPBC. In I. Welch and X. Yi, editors, 13th Australasian Information Security Conference, AISC 2015, Sydney, Australia, January 2015, volume 161 of CRPIT, pages 57–60. Australian Computer Society, 2015.
- J. T. Kohl. The use of encryption in Kerberos for network authentication. In G. Brassard, editor, Advances in Cryptology — CRYPTO ’89, 9th Annual International Cryptology Conference, Santa Barbara, California, USA, August 20–24, 1989, Proceedings, volume 435 of Lecture Notes in Computer Science, pages 35–43. Springer-Verlag, Berlin, 1990.
- A fundamental flaw in the ++AE authenticated encryption mode. J. Math. Cryptol., 12(1):37–42, 2018.
- Forgery attacks on ++AE authenticated encryption mode. In ACSW ’16: Proceedings of the Australasian Computer Science Week Multiconference, Canberra, Australia, February 2–5, 2016, pages 1–9. ACM, 2016.
- Handbook of Applied Cryptography. CRC Press, Boca Raton, 1997.
- C. J. Mitchell. Cryptanalysis of two variants of PCBC mode when used for message integrity. In C. Boyd and J. M. Gonzalez Nieto, editors, Information Security and Privacy, 10th Australasian Conference, ACISP 2005, Brisbane, Australia, July 4–6 2005, Proceedings, number 3574 in Lecture Notes in Computer Science, pages 560–571. Springer-Verlag, Berlin, 2005.
- C. J. Mitchell. Cryptanalysis of the EPBC authenticated encryption mode. In S. D. Galbraith, editor, Cryptography and Coding, 11th IMA International Conference, Cirencester, UK, December 18-20, 2007, Proceedings, volume 4887 of Lecture Notes in Computer Science, pages 118–128. Springer-Verlag, Berlin, 2007.
- C. J. Mitchell. Analysing the IOBC authenticated encryption mode. In C. Boyd and L. Simpson, editors, Information Security and Privacy — 18th Australasian Conference, ACISP 2013, Brisbane, Australia, July 1–3, 2013. Proceedings, volume 7959 of Lecture Notes in Computer Science, pages 1–12. Springer, 2013.
- F. Recacha. IOBC: Un nuevo modo de encadenamiento para cifrado en bloque. In Proceedings: IV Reunion Espanola de Criptologia, Valladolid, September 1996, pages 85–92, 1996.
- F. Recacha. IOC: The most lightweight authenticated encryption mode? Available at https://csrc.nist.rip/groups/ST/toolkit/BCM/documents/proposedmodes/ioc/ioc-spec.pdf, March 2013.
- F. Recacha. ++AE v1.0. Available at https://competitions.cr.yp.to/round1/aev10.pdf, March 2014.
- F. Recacha. ++AE v1.1. Available at https://competitions.cr.yp.to/round1/aev11.pdf, April 2014.
- F. Recacha. Input output chaining (IOC) AE mode revisited. Available at https://inputoutputblockchaining.blogspot.com/, January 2014.
- A. Zuquete and P. Guedes. Transparent authentication and confidentiality for stream sockets. IEEE Micro, 16(3):34–41, May/June 1996.
- A. Zuquete and P. Guedes. Efficient error-propagating block chaining. In M. Darnell, editor, Cryptography and Coding, 6th IMA International Conference, Cirencester, UK, December 17–19, 1997, Proceedings, number 1355 in Lecture Notes in Computer Science, pages 323–334. Springer-Verlag, Berlin, 1997.
Paper Prompts
Sign up for free to create and run prompts on this paper.