
We give a new definition of keyed hash functions and show its relation with strongly universal hash functions and Cartesian authentication codes. We propose an algorithm for a secure keyed hash function and present preliminary result on its performance. The algorithm can be used for fast (about twice the speed of MD5) and secure message authentication.
The demand for security services requiring cryptography is now sufficiently widespread to make appropriate security APIs increasingly valuable tools in the design of secure systems. We will examine some of the APIs currently under development, like GSS-API, and argue that the designers of such APIs have to be explicit about the key management issues relevant to their interfaces.
We present an application of quantum cryptography with faint-pulse interferometry for smart-cards.
The Escrowed Encryption Standard (EES)proposed by U.S. government has gained much attention in the last two years. It was claimed that EES can provide cryptographic protection to unclassified, sensitive data, while at the same time, allow for the decryption of encrypted messages when lawfully authorized. Later, some criticism was proposed to reveal the weakness of the EES proposal.In this paper we propose a new key escrow cryptosystem. The system eliminates many known weaknesses of the EES proposal. Particularly, the new system strengthens the weakest part of the EES proposal, i.e., the checksum generation, and provides other benefits that the original EES proposal did not have.
Four server-aided secret computation protocols, Protocols 1, 2, 3, and 4, for modular exponentiation were proposed by Kawamura and Shimbo in 1993. By these protocols, the client can easily compute the modular exponentiation Md mod N with the help of a powerful server, where N is the product of two large primes. To enhance the security, the client was suggested to use a verification scheme and a slight modification on each proposed protocol. In this paper, we propose two new active attacks to break Protocols 3 and 4, respectively. Even if Protocols 3 and 4 have included the slight modification and verification, the untrusted server can still obtain the secret data d. The client cannot detect these attacks by the proposed verification. To adopt these new attacks, the difficulty of finding the value of the secret data d will be decreased drastically.
Recently, He and Kiesler proposed a new signature scheme whose security is based on both factorization and discrete logarithms to enhance the security of ElGamal's scheme. In this paper, we show that He-Kiesler signature scheme is insecure under the Known-Signature attack.
A clock-controlled shift register that is clocked at least once and at most d + 1 times per output symbol is cryptanalyzed using a constrained embedding approach. Upper bounds on the constrained embedding probabilities that are exponentially small in the string length are derived using finite automata theory and generating functions. A known constrained embedding divide-and-conquer attack on a clock-controlled shift-register developed for at most two clocks at a time (d=1) is thus extended to the general case of arbitrary d. The results show that the minimum length of the observed output sequence needed for successful initial state reconstruction is linear in the shift register length, and at least exponential and at most superexponential in d. This proves that by making d large one cannot achieve the theoretical security against the embedding attack. Experimental results obtained by computer simulations indicate that the required output sequence length is only exponential in d, which would mean that the embedding attack is feasible if d is not too large.
Theory of codes with rank: distance was introduced in 1985, which can be applied to crisscross error correction and also used to build some cryptographical schemes. In this paper, we propose a new identification algorithm based on rank distance codes. This algorithm is simple to describe, it has also advantages in both communications and memory bits.
Periods of interleaved and nonuniformly decimated integer sequences are investigated. A characterization of the period of an interleaved sequence in terms of the constituent periodic integer sequences is first derived. This is then used to generalize the result of Blakley and Purdy on the period of a decimated integer sequence obtained by a periodic nonuniform decimation. The developed technique may be interesting for analyzing the period of various pseudorandom sequences, especially in stream cipher applications.
In this paper we consider multiple encryption schemes built from conventional cryptosystems such as DES. The existing schemes are either vulnerable to variants of meet in the middle attacks, i.e. they do not provide security of the full key or there is no proof that the schemes are as secure as the underlying cipher. We propose a new variant of two-key triple encryption which is not vulnerable to the meet in the middle attack and which uses a minimum amount of key. We can prove a connection between the security of our system and the security of the underlying block cipher.
In some systems, users might want to identify themselves by their pseudonyms. If access control is necessary, then a certificate of authorized access employing pseudonyms must be unforgeable. We call a certificate of authorized access a credential. If different pseudonyms which identify a user are to be unlinkable, the user must be able to choose his pseudonyms at random and to transfer the credential issued on one pseudonym to another pseudonym untraceably. However, in order to prevent forgery of the certificate, pseudonyms must be formed in a specific way. This work presents a pseudonym validation process based on discrete logarithms without using cut-and-choose. The certificates issued with pseudonyms are unforgeable. The privacy of users is protected unconditionally. This pseudonym system has the novel feature that each user has a validated public key relevant to each pseudonym, so that signatures can be made by pseudonyms.
In this paper we consider the secret reconstruction problem in a secret sharing scheme. We show how to use a slowly-information-revealing process to achieve a fair reconstruction of a shared secret. We give a detailed analysis on the advantage cheaters could gain in such a process.
Statistical tests have been applied to measures obtained from partitioning the keystream of a stream cipher into subsets of a given length. Similarly, the strength of a block cipher has been measured by applying statistical tests to subsets obtained from both the input and output blocks. There are problems in applying these tests as the size of the subsets increases; We propose a novel method based on the classical occupancy problem to deal with larger subsets in testing for randomness in a keystream in the case of a stream cipher and for independence between subsets of input and output blocks in the case of a block cipher.
The public debate on cryptography policy assumes that the issue is between the state's desire for effective policing and the privacy of the individual. We show that this is misguided. We start off by examining the state of current and proposed legislation in Europe, most of which is concerned with preserving national intelligence capabilities by restricting the export, and in cases even the domestic use, of cryptography, on the pretext that it may be used to hide information from law officers. We then survey the currently fielded cryptographic applications, and find that very few of them are concerned with secrecy: most of them use crypto to prevent fraud, and are thus actually on the side of law enforcement. However, there are serious problems when we try to use cryptography in evidence. We describe a number of cases in which such evidence has been excluded or discredited, and with a growing proportion of the world economy based on transactions protected by cryptography, this is likely to be a much more serious problem for law enforcement than occasional use of cryptography by criminals.
''Commercial Key Escrow (CKE)'', and an earlier ''Software Key Escrow (SKE) scheme, have been proposed by Trusted Information Systems Inc. (TIS) in the USA as a possible compromise scheme to meet the demands of commerce and industry for new levels of information security, particularly transaction and message confidentiality in an international and national networked environment, while meeting law enforcement demands for continued effectiveness of telecommunications line-tapping ability. These latter requirements relate to the perceived need by law enforcement agencies to make use of legitimate authorised line-tapping capabilities for the gathering of appropriate intelligence and/or evidence for the purpose of fulfilling perceived roles in the protection of society from criminal activity against the potential case where such line-taps produce intercepts that are encrypted. CKE, involving the incorporation of software based cryptography in computer and network systems with associated key recovery data transmitted during data network activity and provision of ''Data Recovery Centres (DRC)'', is seen as presenting a new solution to the problems encountered in the USA with the ''Clipper'' initiative in that country announced in 1993.This paper examines the CKE/SKE proposals in an Australian and international context and sets the proposal against the more general debate on cryptography, its technology and usage, and public policy. A likely scenario is suggested for Australia involving the incorporation of backup and recovery and network directory services into the encryption scheme and the use of Australia Post, and indeed any national post office structure, as an ideal candidate for trials of both the technology and public/business acceptance of this overall structure. More basic principles of ''freedom-of-speech'' are also raised in conjunction with this overall analysis of a concrete proposal.
The goal of the Computer Architecture for Secure Systems (CASS) project [1] is to develop an architecture and tools to ensure the security and integrity of software in distributed systems. CASS makes use of various cryptographic techniques at the operating system kernel level to authenticate software integrity. The CASS shell, the work described in this paper, is on the other hand a secure shell implemented on top of UNIX1 System V Release 4.2 (UNIX SVR4.2) to achieve the same purpose but in an operating system independent manner. The CASS shell carries out cryptographic authentication of executable files based on the MD5 Message-Digest algorithm [2] and presents a closed computing environment in which system utilities are safeguarded against unauthorised alteration and users are prevented from executing unsafe commands. In order to provide cryptographic authentication and other cryptographic functions such as public-key based signatures, in hardware, the work has also involved the incorporation of an encryption hardware sub-system into SVR4.2 operating on an Intel 80×86 hardware platform. The paper describes the structure and features of the CASS shell and the development and performance of both the hardware and software implementations of the cryptographic functions it uses.
A finite nonlinear automaton for a one-key blockcipher cryptosystem is presented. The key defines the automaton. The mapping from the “keyspace” to the “automaton-space” is one to one. Similar to other cryptosystems, encryption and decryption is done by repeating a number of simple steps called “rounds”. The number of rounds and the blocksize can be variable and does not depend on the key. The statistical properties measured on the ciphertext are satisfactory and in the same range as the properties of DES (Data Encryption Standard).
We present an algorithm allowing the rapid identification of low order nonlinear Boolean functions. An extension of the method allowing the identification of good low order approximations (if they exist) is then described. We discuss the application of the method to cryptanalysis of black-box cipher functions. We present results indicating that the method can be expected to perform better than random search in locating good low order approximating Boolean functions. An expression for the effectiveness of the attack is derived, and it is shown that highly nonlinear balanced Boolean functions constructed as modified low order bent functions are particularly vulnerable to the attack. The required tradeoff in resisting both linear and quadratic approximation is also discussed.
Debate on encryption in Global Information Infrastructures has been complicated by issues relating to law enforcement. This paper looks at a technique for limiting the use of anonymous cash for illicit purposes to an acceptable level. It also argues that the majority of users will not require high level encryption systems to protect their privacy and hence would not require the keys to their encryption schemes to be escrowed. It proposes a scheme of Differential Key Escrow (DKE) where only the keys of high level encryption systems used by government and larger corporations would be held in escrow by the organisation.