Context Discovery and Commitment Attacks - How to Break CCM, EAX, SIV, and More

Context Discovery and Commitment Attacks - How to Break CCM, EAX, SIV, and More
复制标题

DOI:
10.1007/978-3-031-30634-1_13
复制
发表时间:
2023
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Sanketh Menda;Julia Len;Paul Grubbs;Thomas Ristenpart
Sanketh Menda;Julia Len;Paul Grubbs;Thomas Ristenpart
中科院分区:
其他
文献类型:
--
作者:
Sanketh Menda;Julia Len;Paul Grubbs;Thomas Ristenpart

文献摘要

相似文献

最近的一系列工作强调了上下文承诺安全的重要性,它要求关联数据验证加密 (AEAD) 方案不会在两个不同的对抗性选择的上下文(秘密密钥、关联数据和随机数)下解密相同的对抗性选择的密文。尽管最近发生了一系列攻击,但围绕上下文承诺仍然存在许多悬而未决的问题;最明显的是,我们对 CCM、EAX 和 SIV 等重要方案的承诺安全性一无所知。我们解决了这些悬而未决的问题以及更多问题。我们的方法是,首先,引入一个新的框架,帮助我们根据上下文的哪些部分受到对抗性控制来更精细地定义上下文承诺安全性。我们继续制定一个新的安全概念,称为上下文可发现性,它可以被视为类似于散列文献中的原像抵抗。我们表明,无限制的上下文承诺安全性(对手控制所有两个上下文)意味着包含实践中使用的大多数方案的一类方案的上下文可发现性安全性。然后,我们展示了针对一系列广泛的 AEAD 方案的新上下文发现攻击,包括 CCM、EAX、SIV、GCM 和 OCB3,并且根据我们的总体结果,这给出了针对它们的新的无限制上下文提交攻击。最后,我们探讨了原始 SIV 模式的受限上下文提交安全性的情况,对于这种情况,先前的攻击技术都不起作用(包括我们基于上下文发现的攻击技术)。尽管如此,我们仍然能够使用 Wagner 的 k 树算法对广义生日问题进行新颖的攻击。
A line of recent work has highlighted the importance of context commitment security, which asks that authenticated encryption with associated data (AEAD) schemes will not decrypt the same adversarially-chosen ciphertext under two different, adversarially-chosen contexts (secret key, associated data, and nonce). Despite a spate of recent attacks, many open questions remain around context commitment; most obviously nothing is known about the commitment security of important schemes such as CCM, EAX, and SIV.We resolve these open questions, and more. Our approach is to, first, introduce a new framework that helps us more granularly define context commitment security in terms of what portions of a context are adversarially controlled. We go on to formulate a new security notion, called context discoverability, which can be viewed as analogous to preimage resistance from the hashing literature. We show that unrestricted context commitment security (the adversary controls all of the two contexts) implies context discoverability security for a class of schemes encompassing most schemes used in practice. Then, we show new context discovery attacks against a wide set of AEAD schemes, including CCM, EAX, SIV, GCM, and OCB3, and, by our general result, this gives new unrestricted context commitment attacks against them.Finally, we explore the case of restricted context commitment security for the original SIV mode, for which no prior attack techniques work (including our context discovery based ones). We are nevertheless able to give a novelattack using Wagner’s k-tree algorithm for the generalized birthday problem.