The Curse of Small Domains: New Attacks on Format-Preserving Encryption
The Curse of Small Domains: New Attacks on Format-Preserving Encryption
复制标题
小域的诅咒:对格式保留加密的新攻击
DOI:
10.1007/978-3-319-96884-1_8
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Viet Tung Hoang, Stefano Tessaro
中科院分区:
文献类型:
--
作者:
Viet Tung Hoang, Stefano Tessaro
Format-preserving encryption (FPE) produces ciphertexts which have the same format as the plaintexts. Building secure FPE is very challenging, and recent attacks (Bellare, Hoang, Tessaro, CCS ’16; Durak and Vaudenay, CRYPTO ’17) have highlighted security deficiencies in the recent NIST SP800-38G standard. This has left the question open of whether practical schemes with high security exist.In this paper, we continue the investigation of attacks against FPE schemes. Our first contribution are new known-plaintext message recovery attacks against Feistel-based FPEs (such as FF1/FF3 from the NIST SP800-38G standard) which improve upon previous work in terms of amortized complexity in multi-target scenarios, where multiple ciphertexts are to be decrypted. Our attacks are also qualitatively better in that they make no assumptions on the correlation between the targets to be decrypted and the known plaintexts. We also surface a new vulnerability specific to FF3 and how it handles odd length domains, which leads to a substantial speedup in our attacks.We also show the first attacks against non-Feistel based FPEs. Specifically, we show a strong message-recovery attack for FNR, a construction proposed by Cisco which replaces two rounds in the Feistel construction with a pairwise-independent permutation, following the paradigm by Naor and Reingold (JoC, ’99). We also provide a strong ciphertext-only attack against a variant of the DTP construction by Brightwell and Smith, which is deployed by Protegrity within commercial applications. All of our attacks show that existing constructions fall short of achieving desirable security levels. For Feistel and the FNR schemes, our attacks become feasible on small domains, e.g., 8 bits, for suggested round numbers. Our attack against the DTP construction is practical even for large domains. We provide proof-of-concept implementations of our attacks that verify our theoretical findings.
登录
查看更多内容
DOI:
10.1007/978-3-319-63715-0_23
发表时间:
2017
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
作者:
F. Durak;S. Vaudenay
通讯作者:
S. Vaudenay
DOI:
10.1007/978-3-319-12060-7_10
发表时间:
2014
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
作者:
Sashank Dara;S. Fluhrer
通讯作者:
S. Fluhrer
DOI:
10.1007/978-3-642-40041-4_22
发表时间:
2013
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
作者:
Thomas Ristenpart;Scott Yilek
通讯作者:
Scott Yilek
DOI:
--
发表时间:
2010
期刊:
--
影响因子:
--
作者:
Thomas Peyrin;J. Stern
通讯作者:
Thomas Peyrin;J. Stern