An Analysis of Parallelizable Authenticated Encryption
Kazuhiko Minematsu NEC Corporation Joint work with Akiko Inoue
Asian Symmetric-key Workshop 2018 Nov 14 Kolkata, India
1
Authenticated Encryption Kazuhiko Minematsu NEC Corporation Joint - - PowerPoint PPT Presentation
An Analysis of Parallelizable Authenticated Encryption Kazuhiko Minematsu NEC Corporation Joint work with Akiko Inoue Asian Symmetric-key Workshop 2018 Nov 14 Kolkata, India 1 Cryptanalysis of OCB2 (ePrint 2018/1040) Kazuhiko Minematsu NEC
Asian Symmetric-key Workshop 2018 Nov 14 Kolkata, India
1
Asian Symmetric-key Workshop 2018 Nov 14 Kolkata, India
2
(ePrint 2018/1040)
3
Alice Bob Eve Ciphertext Plaintext Key Key
4
5
6
[RBBK01] Rogaway, Bellare, Black, Krovetz : OCB: A block-cipher mode of operation for efficient authenticated encryption. ACM CCS 2001 [Rog04] Rogaway : Efficient Instantiations of Tweakable Blockciphers and Refinements to Modes OCB and PMAC. ASIACRYPT 2004 [KR11] Krovetz, Rogaway : The Software Performance of Authenticated-Encryption Modes. FSE 2011
7
8
[Fer02] Ferguson. Collision attacks on OCB. Comments to NIST. [ABLMMY14] Andreeva, Bogdanov, Luykx, Mennink, Mouha, and Yasuda. How to Securely Release Unverified Plaintext in Authenticated Encryption. Asiacrypt 2014. [ADL17] Ashur, Dunkelman, Luykx. Boosting Authenticated Encryption Robustness with Minimal Modifications. CRYPTO 2017. [AY13] Aoki and Yasuda. The Security of the OCB Mode of Operation without the SPRP Assumption. ProvSec 2013. [BN17] Bhaumik and Nandi. Improved Security for OCB3. Asiacrypt 2017. [SWZ12] Sun, Wang, Zhang. Collision Attacks on Variant of OCB Mode and Its Series. Inscrypt 2012.
9
10
11
AE-Enc K N A M C T AE-Dec K N A C M (valid) or ⊥ (invalid) T (N, A, C, T)
12
Adversary AE Enc-o $
Adversary AE Enc-o AE Dec-o
“AE’” or “$” (win if ≠⊥ )
13
14
15
16
17
18
19
20
E
෨ 𝐹
෨ 𝑄
21
22
23
24
F(A) – Advauth G(A) = AdvIND F,G(A) when Advauth F(A) = Pr[AF => 1] for
some game of A querying F
25
Adversary AE Enc-o AE Dec-o (win if ≠⊥ ) (N,A,C,T)
[BGM94] Bellare, Goldreich, Mityagin. The Power of Verification Queries in Message Authentication and Authenticated Encryption. ePrint 2004/309. [MLI13] Minematsu, Luck, Iwata. Improved Authenticity Bound of EAX, and Refinements. ProvSec 2013.
26
27
28
[Min14] Minematsu. Parallelizable Rate-1 Authenticated Encryption from Pseudorandom Functions. Eurocrypt 2014. [GJMN16] Granger, Jovanovic, Mennink, Neves. Improved Masking for Tweakable Blockciphers with Applications to Authenticated Encryption. Eurocrypt 2016.
29
[MM08] Minematsu and Matsushima. Generalization and Extension of XEX* Mode. IEICE-A 2009.
30
[Pot18] Poettering. Breaking the confidentiality of OCB2. ePrint 2018/1087 [Iwa18] Iwata. Plaintext recovery attack of OCB2. ePrint 2018/1090
31
32