Towards Understanding the Known-Key Security of Block Ciphers

被引:23
|
作者
Andreeva, Elena [1 ,2 ]
Bogdanov, Andrey [3 ]
Mennink, Bart [1 ,2 ]
机构
[1] Katholieke Univ Leuven, Dept Elect Engn, ESAT COSIC, Leuven, Belgium
[2] iMinds, Leuven, Belgium
[3] Tech Univ Denmark, Lyngby, Denmark
来源
关键词
Block ciphers; Known-key security; Known-key distinguishers; Indiffierentiability; RANDOM ORACLE MODEL; MERKLE-DAMGARD; IDEAL CIPHER; HASH FUNCTIONS; DISTINGUISHERS; ATTACKS; FEISTEL; INDIFFERENTIABILITY; PERMUTATIONS; CONSTRUCT;
D O I
10.1007/978-3-662-43933-3_18
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Known-key distinguishers for block ciphers were proposed by Knudsen and Rijmen at ASIACRYPT 2007 and have been a major research topic in cryptanalysis since then. A formalization of known-key attacks in general is known to be difficult. In this paper, we tackle this problem for the case of block ciphers based on ideal components such as random permutations and random functions as well as propose new generic known-key attacks on generalized Feistel ciphers. We introduce the notion of known-key indiffierentiability to capture the security of such block ciphers under a known key. To show its meaningfulness, we prove that the known-key attacks on block ciphers with ideal primitives to date violate security under known-key indiffierentiability. On the other hand, to demonstrate its constructiveness, we prove the balanced Feistel cipher with random functions and the multiple Even-Mansour cipher with random permutations known-key indifferentiable for a sufficient number of rounds. We note that known-key indiffierentiability is more quickly and tightly attained by multiple Even-Mansour which puts it forward as a construction provably secure against known-key attacks.
引用
收藏
页码:348 / 366
页数:19
相关论文
共 50 条
  • [1] Strengthening the Known-Key Security Notion for Block Ciphers
    Cogliati, Benoit
    Seurin, Yannick
    FAST SOFTWARE ENCRYPTION (FSE 2016), 2016, 9783 : 494 - 513
  • [2] Known-key distinguishers for some block ciphers
    Knudsen, Lars R.
    Rijmen, Vincent
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2007, 2007, 4833 : 315 - +
  • [3] Known-Key Attack on SM4 Block Cipher
    Kang, HyungChul
    Hong, Deukjo
    Sung, Jaechul
    Hong, Seokhie
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2017, E100A (12): : 2985 - 2990
  • [4] Naor-Reingold Goes Public: The Complexity of Known-Key Security
    Soni, Pratik
    Tessaro, Stefano
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2018, PT III, 2018, 10822 : 653 - 684
  • [5] Known and Chosen Key Differential Distinguishers for Block Ciphers
    Nikolic, Ivica
    Pieprzyk, Josef
    Sokolowski, Przemyslaw
    Steinfeld, Ron
    INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2010, 2011, 6829 : 29 - +
  • [6] Known-Key Distinguisher on Full PRESENT
    Blondeau, Celine
    Peyrin, Thomas
    Wang, Lei
    ADVANCES IN CRYPTOLOGY, PT I, 2015, 9215 : 455 - 474
  • [7] Revisiting Gilbert’s known-key distinguisher
    Lorenzo Grassi
    Christian Rechberger
    Designs, Codes and Cryptography, 2020, 88 : 1401 - 1445
  • [8] Known-Key Attack-Resilient Cluster Key Management
    Jeong, Gowun
    Yang, Hyun S.
    Yeo, Sang-Soo
    Seo, Yong-Ho
    2013 EIGHTH INTERNATIONAL CONFERENCE ON BROADBAND, WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS (BWCCA 2013), 2013, : 261 - 264
  • [9] Revisiting Gilbert's known-key distinguisher
    Grassi, Lorenzo
    Rechberger, Christian
    DESIGNS CODES AND CRYPTOGRAPHY, 2020, 88 (07) : 1401 - 1445
  • [10] On the Impact of Known-Key Attacks on Hash Functions
    Mennink, Bart
    Preneel, Bart
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2015, PT II, 2015, 9453 : 59 - 84