Partition Oracles from Weak Key Forgeries

Partition Oracles from Weak Key Forgeries
复制标题

将 Oracle 与弱密钥伪造进行分区

DOI:
--
复制
发表时间:
2021
期刊:
Cryptology and Network Security
影响因子:
--
通讯作者:
C. Cid
C. Cid
中科院分区:
--
文献类型:
--
作者:
Marcel Armour;C. Cid

文献摘要

参考文献

被引文献

相似文献

。在这项工作中,我们展示了如何利用针对基于多项式哈希的认证加密(AE)方案(如AES-GCM)的弱密钥伪造来发起分区预言攻击。分区Oracle攻击最近由Len等人引入。(Usenix‘21)作为一种新的解密错误预言,其概念上将密文作为输入并输出解密密钥是否属于某个已知的密钥子集。分区Oracle攻击允许对手同时查询多个密钥,从而导致对低熵密钥(例如,从密码派生的密钥)的实际攻击。弱密钥伪造在Procter和Cid(FSE‘13)的工作中得到了系统的处理,他们展示了如何构造MAC伪造来有效地测试解密密钥是否在某个(任意)目标密钥集中。因此,弱密钥伪造似乎自然地适合于构造划分预言;我们证明了情况确实如此,并讨论了这种攻击的一些实际应用。我们的攻击适用于将AE方案与静态会话密钥一起使用的设置,并且具有特别的优势,即攻击者可以完全控制底层明文,允许满足对底层明文的任何格式检查-包括那些旨在抵御分区Oracle攻击的检查。前人的工作表明,在特定的环境下,密钥承诺是AE方案的一个重要的安全性质。我们的结果表明,抵抗弱密钥伪造应该被认为是一个相关的设计目标。最后,我们的结果强化了这样一个信息,即永远不应该使用弱密码来派生加密密钥。
. In this work, we show how weak key forgeries against polynomial hash based Authenticated Encryption (AE) schemes, such as AES-GCM, can be leveraged to launch partitioning oracle attacks. Partitioning oracle attacks were recently introduced by Len et al. (Usenix’21) as a new class of decryption error oracle which, conceptually, takes a ciphertext as input and outputs whether or not the decryption key belongs to some known subset of keys. Partitioning oracle attacks allow an adversary to query multiple keys simultaneously, leading to practical attacks against low entropy keys (e. g. those derived from passwords). Weak key forgeries were given a systematic treatment in the work of Procter and Cid (FSE’13), who showed how to construct MAC forgeries that effectively test whether the decryption key is in some (arbitrary) set of target keys. Consequently, it would appear that weak key forgeries naturally lend themselves to constructing partition oracles; we show that this is indeed the case, and discuss some practical applications of such an attack. Our attack applies in settings where AE schemes are used with static session keys, and has the particular advantage that an attacker has full control over the underlying plaintexts, allowing any format checks on underlying plaintexts to be met – including those designed to mitigate against partitioning oracle attacks. Prior work demonstrated that key commitment is an important security property of AE schemes, in particular settings. Our results suggest that resistance to weak key forgeries should be considered a related design goal. Lastly, our results reinforce the message that weak passwords should never be used to derive encryption keys.
分区 Oracle 攻击
DOI: --
发表时间: 2021
期刊: USENIX Security Symposium
影响因子: --
作者:
Len, Julia;Grubbs, Paul;Ristenpart, Thomas
通讯作者: Ristenpart, Thomas
快速邮件邮资盖印:从隐形蝾螈到加密
DOI: --
发表时间: 2018
期刊: Advances in Cryptology - CRYPTO
影响因子: --
作者:
Dodis, Yevgeniy;Grubbs, Paul;Ristenpart, Thomas;Woodage, Joanne
通讯作者: Woodage, Joanne