In this paper, we define a special class of systems of linear equations over finite fields that arise in the security analysis of various MAC and PRF modes. We establish lower bounds on the number of solutions for these systems under specific restrictions and use them to derive tight PRF security for several constructions. Specifically, we prove security up to O(2^3n/4) queries for the single-keyed variant of the Double-block Hash-then-Sum (DBHtS) construction, called 1k-DBHtS, assuming appropriate hash function properties. We show that the single-keyed variants of PMAC+ and LightMAC+, called 1k-PMAC+ and 1k-LightMAC+ satisfy these properties, achieving security up to O(2^3n/4) queries. Additionally, we show that the sum of r independent Even-Mansour ciphers is secure up to O(2^r/r+1n) queries.
This paper studies the security of key derivation functions (KDFs), a central class of cryptographic algorithms used to derive multiple independent-looking keys (each associated with a particular context) from a single secret. The main security requirement is that these keys are pseudorandom (i.e., the KDF is a pseudorandom function). This paper initiates the study of an additional security property, called key control (KC) security, first informally put forward in a recent update to NIST Special Publication (SP) 800-108 standard for KDFs. Informally speaking, KC security demands that, given a known key, it is hard for an adversary to find a context that forces the KDF-derived key for that context to have a property that is specified a-priori and is hard to satisfy (e.g., that the derived key consists mostly of 0s, or that it is a weak key for a cryptographic algorithm using it). We provide a rigorous security definition for KC security, and then move on to the analysis of the KDF constructions specified in NIST SP 800-108. We show, via security proofs in the random oracle model, that the proposed constructions based on XOFs or hash functions can accommodate for reasonable security margins (i.e., 128-bit security) when instantiated from KMAC and HMAC. We also show, via attacks, that all proposed block-cipher based modes of operation (while implementing mitigation techniques to prevent KC security attacks affecting earlier version of the standard) only achieve at best 72-bit KC security for 128-bit blocks, as with AES.
In this work, we examine online authenticated encryption with variable expansion. We follow a notion where both encryption and decryption are online, and security is ensured in the RUP (Release of Unverified Plaintext) setting. Then we propose a generic way of obtaining an online authenticated encryption mode from a tweakable online encryption mode based on the encode-then-encipher paradigm (Bellare and Rogaway, Asiacrypt 2000). To instantiate our generic scheme, we start with proposing a provably-secure tweakable online encryption mode called - , a tweakable version of (Bhaumik and Nandi, ToSC 2016(2)), and then plug it into our generic scheme to obtain , a provably-secure online authenticated encryption mode. As an application, we propose a primitive we call a bidirectional online channel suited for communication between lightweight devices.
This paper studies the security of key derivation functions (KDFs), a central class of cryptographic algorithms used to derive multiple independent-looking keys (each associated with a particular context) from a single secret. The main security requirement is that these keys are pseudorandom (i.e., the KDF is a pseudorandom function). This paper initiates the study of an additional security property, called key control (KC) security, first informally put forward in a recent update to NIST Special Publication (SP) 800-108 standard for KDFs. Informally speaking, KC security demands that, given a known key, it is hard for an adversary to find a context that forces the KDF-derived key for that context to have a property that is specified a-priori and is hard to satisfy (e.g., that the derived key consists mostly of 0s, or that it is a weak key for a cryptographic algorithm using it). We provide a rigorous security definition for KC security, and then move on to the analysis of the KDF constructions specified in NIST SP 800-108. We show, via security proofs in the random oracle model, that the proposed constructions based on XOFs or hash functions can accommodate for reasonable security margins (i.e., 128-bit security) when instantiated from KMAC and HMAC. We also show, via attacks, that all proposed block-cipher based modes of operation (while implementing mitigation techniques to prevent KC security attacks affecting earlier version of the standard) only achieve at best 72-bit KC security for 128-bit blocks, as with AES.
Authenticated Encryption with Associated Data (AEAD) schemes have become a powerful solution for addressing contemporary security challenges. Within the recipients of recognition from the CAESAR competition, COLM AEAD emerges as a distinctive focus of interest within the realm of cryptanalysis. It draws significant attention, specifically in the context of endeavors related to universal forgery, retrieval of plaintext, and the exploration of tag guessing attacks. Recently, Ulusoy et al. (JISA 2022) proposed attacks on COLM by constructing simulation models of the encryption or decryption oracles of the underlying block cipher (SEBC or SDBC). To counter these attacks, they also suggested potential enhancements for COLM. Thus, this paper aims to delve into the security aspects of those variants of COLM discussed by Ulusoy et al. (JISA 2022). In this paper, firstly, we construct SEBC and SDBC of COLM with a generalized linear mixing function and propose all three types of attacks using SEBC and SDBC. While Datta et al. (IACR ToSC 2017) previously investigated the INT-RUP security of COLM with a generalized linear mixing function, the construction of SEBC/SDBC for such a scenario remained an open question until now. Additionally, we present a new SEBC/SDBC construction of COLM where the whitening mask L is encrypted using a separate key distinct from the main key. Furthermore, we consider situations where the masking values in the associated data processing are altered, preventing conventional methods like Lu’s (ASIACCS 2017) from recovering L. Nevertheless, we propose an alternative method to recover L, facilitating cryptanalysis of this particular variant of COLM. This analysis sheds light on the security strengths and vulnerabilities of these variants, offering valuable insights for further advancements in COLM.
The public comments received for the review process for NIST (SP) 800-38A pointed out two important issues that most companies face: (1) the limited security that AES can provide due to its 128-bit block size and (2) the problem of nonce-misuse in practice. In this paper, we provide an alternative solution to these problems by introducing two optimally secure deterministic authenticated encryption (DAE) schemes, denoted as DENC1 and DENC2 respectively. We show that our proposed constructions improve the state-of-the-art in terms of security and efficiency. Specifically, DENC1 achieves a robust security level of O(r^2σ ^2ℓ /2^2n) , while DENC2 attains a near-optimal security level of O(rσ /2^n) , where σ is the total number of blocks, ℓ is maximum number of blocks in each query, and r is a user-defined parameter closely related to the rate of the construction. Our research centers on the development of two IV-based encryption schemes, referred to as IV1 and IV2, which respectively offer security levels of O(r^2σ ^2ℓ /2^2n) and O(rσ /2^n) . Notably, both of our DAE proposals are nearly rate 1/2 constructions. In terms of efficiency, our proposals compare favorably with state-of-the-art AE modes on contemporary microprocessors.
The collision-resistant hash function is an early cryptographic primitive that finds extensive use in various applications. Remarkably, the Merkle-Damgård and Merkle tree hash structures possess the collision-resistance preserving property, meaning the hash function remains collision-resistant when the underlying compression function is collision-resistant. This raises the intriguing question of whether reducing the number of underlying compression function calls with the collision-resistance preserving property is possible. In pursuit of addressing these inquiries, we prove that for an ℓ n -to- s n -bit collision-resistance preserving hash function designed using r t n -to- n -bit compression function calls, we must have r ≥ ⌈ ( ℓ − s ) / ( t − 1 ) ⌉ . Throughout the paper, all operations other than the compression function are assumed to be linear (which we call linear hash mode).
The prefix-free PRF (pseudorandom function) security of a cascade function based on a compression function f against a q-query distinguisher is reduced to a q-query PRF security of f with a tightness gap ℓ q where ℓ represents the length of the longest query among all q queries. In this paper, we have shown a new reduction which is also applicable to multiuser setup and improves the tightness gap for both adaptive and non-adaptive distinguishers. As an immediate application of our result, we have shown multiuser security of NMAC, HMAC and many other known MACs in the standard model. Moreover, the tightness gap is improved in comparison with known single-user analysis. We also have shown a similar tightness gap for the single-keyed version of NMAC. As a result, the constants ipad and opad used in HMAC and relying upon the PRB (pseudorandom bit) assumption on the underlying compression function become redundant.
In this work we present the COLM authenticated encryption (AE) scheme which is the second of the two winners in the defense in depth category of the CAESAR competition. COLM realizes a nonce-based authenticated encryption with associated data and uses the popular AES blockcipher as its underlying primitive. We propose two possible blockcipher instantiations (with key of length 128 or 256 bits). We also define two COLM modes of operation variants: a primary COLM _0 mode for general purpose applications, and a COLM _τ variant with intermediate tag generation/verification geared to support low-end devices and applications where frequent verification is required. COLM is designed with security, simplicity, and efficiency in mind. The main design goal of COLM is high security: a primary feature of the defense in depth CAESAR category. COLM provides security beyond the traditional AE security. First, COLM is secure against nonce misuse, namely, it enables security in adversarial settings where the nonce inputs to the AE scheme repeat. In contrast to standardized and popular AE algorithms, such as GCM and OCB1-3 modes, whose AE security trivially breaks down when the nonce is repeated, COLM ensures both confidentiality and authenticity (AE) security with repeated nonces. Second, our COLM _τ variant enables increased security levels in situations where release of unverified ciphertext (RUP) occurs due to its ability to limit a potential leakage by frequent verifications. In this work we prove COLM secure with respect to both confidentiality and authenticity (AE) security under nonce misuse in the well-known provable security framework. Our proofs show that COLM maintains n/2-bit security levels for block sizes of n bits. Furthermore, due to the inherent parallelism on both mode and primitive levels, our software performance results show that the price paid for enhanced security does come at the cost of minimal efficiency losses. More concretely, we implement GCM, COLM, and Deoxys-II on the Kaby Lake and Coffee lake Intel platforms. Compared to the other winner in the defense in depth category Deoxys-II, our AE design COLM _0 performs 10–20 _0 is around 5
Liskov, Rivest and Wagner laid the theoretical foundations for tweakable block ciphers (TBC). In a seminal paper, they proposed two (up to) birthday-bound secure design strategies - LRW1 and LRW2 to convert any block cipher into a TBC. Several of the follow-up works consider cascading of LRW-type TBCs to construct beyond-the-birthday bound (BBB) secure TBCs. Landecker et al. demonstrated that just tworound cascading of LRW2 can already give a BBB security. Bao et al. undertook a similar exercise in context of LRW1 with TNT - a threeround cascading of LRW1 - that has been shown to achieve BBB security as well. In this paper, we present a CCA distinguisher on TNT that achieves a non-negligible advantage with O(2n/2) queries, directly contradicting the security claims made by the designers. We provide a rigorous and complete advantage calculation coupled with experimental verification that further support our claim. Next, we provide new and simple proofs of birthday-bound CCA security for both TNT and its single-key variant, which confirm the tightness of our attack. Furthering on to a more positive note, we show that adding just one more block cipher call, referred as 4-LRW1, does not just re-establish the BBB security, but also amplifies it up to 23n/4 queries. As a side-effect of this endeavour, we propose a new abstraction of the cascaded LRW-design philosophy, referred to as the LRW+ paradigm, comprising two block cipher calls sandwiched between a pair of tweakable universal hashes. This helps us to provide a modular proof covering all cascaded LRW constructions with at least 2 rounds, including 4-LRW1, and its more established relative, the well-known CLRW2, or more aptly, 2-LRW2.
Substitution-Permutation Networks (SPNs) are a popular and powerful technique for designing block ciphers. Confusion-Diffusion Networks (CDNs), as formalised by Dodis et al. at Eurocrypt'16, treat unkeyed SPNs as a means of extending the domain of public permutations. Dodis et al. showed that 5-round CDNs are indifferentiable from an ideal permutation, and subsequent works by Da et al. at Indocrypt'21 and Nandi et al. at C2SI'23 have established that 2-round CDNs cannot achieve the weaker notion of sequential indifferentiability even with non-linear diffusion layers. In this paper we show for the first time that 3-round CDNs with linear diffusion layers can achieve indifferentiability from an ideal permutation.
Estimating the size of the union of a stream of sets S-1, S-2, . . . , S-M where each set is a subset of a known universe Omega is a fundamental problem in data streaming. This problem naturally generalizes the well-studied F-0 estimation problem in the streaming literature, where each set contains a single element from the universe. We consider the general case when the sets S-i can be succinctly represented and allow efficient membership, cardinality, and sampling queries (called a Delphic family of sets). A notable example in this framework is the Klee's Measure Problem (KMP), where every set S-i is an axis-parallel rectangle in d-dimensional spaces (Omega = [Delta](d) where [Delta] : {1, . . . ,Delta} and Delta is an element of N). Recently, Meel, Chakraborty, and Vinodchandran (PODS-21, PODS-22) designed a streaming algorithm for (epsilon, delta)-estimation of the size of the union of set streams over Delphic family with space and update time complexity O(log(3) vertical bar Omega vertical bar/epsilon(2) . log 1/delta) and (O) over tilde (log(4) vertical bar Omega vertical bar/epsilon(2) . log 1/delta), respectively. This work presents a new, sampling-based algorithm for estimating the size of the union of Delphic sets that has space and update time complexity (O) over tilde (log(2) vertical bar Omega vertical bar/epsilon(2) . log 1/delta). This improves the space complexity bound by a log Omega vertical bar factor and update time complexity bound by a log(2) vertical bar Omega vertical bar factor. A critical question is whether quadratic dependence of log Omega vertical bar on space and update time complexities is necessary. Specifically, can we design a streaming algorithm for estimating the size of the union of sets over Delphic family with space and complexity linear in log Omega vertical bar and update time poly(log vertical bar Omega vertical bar)? While this appears technically challenging, we show that establishing a lower bound of omega(log vertical bar Omega vertical bar) with poly(log vertical bar Omega vertical bar) update time is beyond the reach of current techniques. Specifically, we show that under certain hard-to-prove computational complexity hypothesis, there is a streaming algorithm for the problem with optimal space complexity O(log vertical bar Omega vertical bar) and update time poly(log vertical bar Omega vertical bar). Thus, establishing a space lower bound of omega(log vertical bar Omega vertical bar) will lead to break-through complexity class separation results.
The Ascon cipher suite has recently become the preferred standard in the NIST Lightweight Cryptography standardization process. Despite its prominence, the initial dedicated security analysis for the Ascon mode was conducted quite recently. This analysis demonstrated that the Ascon AEAD mode offers superior security compared to the generic Duplex mode, but it was limited to a specific scenario: single-user nonce-respecting, with a capacity strictly larger than the key size. In this paper, we eliminate these constraints and provide a comprehensive security analysis of the Ascon AEAD mode in the multi-user setting, where the capacity need not be larger than the key size. Regarding data complexity D and time complexity T, our analysis reveals that Ascon achieves AEAD security when T is bounded by min{2κ/μ,2c} (where κ is the key size, and μ is the number of users), and DT is limited to 2b (with b denoting the size of the underlying permutation, set at 320 for Ascon). Our results align with NIST requirements, showing that Ascon allows for a tag size as small as 64 bits while supporting a higher rate of 192 bits, provided the number of users remains within recommended limits. However, this security becomes compromised as the number of users increases significantly. To address this issue, we propose a variant of the Ascon mode called LK-Ascon, which enables doubling the key size. This adjustment allows for a greater number of users without sacrificing security, while possibly offering additional resilience against quantum key recovery attacks. We establish tight bounds for LK-Ascon, and furthermore show that both Ascon and LK-Ascon maintain authenticity security even when facing nonce-misuse adversaries.
Sponge based constructions have gained significant popularity for designing lightweight authenticated encryption modes. Most of the authenticated ciphers following the Sponge paradigm can be viewed as variations of the Transform-then-permute construction. It is known that a construction following the Transform-then-permute paradigm provides security against any adversary having data complexity D and time complexity T as long as D T ≪ 2 b - r . Here, b represents the size of the underlying permutation, while r pertains to the rate at which the message is injected. The above result demonstrates that an increase in the rate leads to a degradation in the security of the constructions, with no security guaranteed to constructions operating at the full rate, where r = b . This present study delves into the exploration of whether adding some auxiliary states could potentially improve the security of the Transform-then-permute construction. Our investigation yields an affirmative response, demonstrating that a special class of full rate Transform-then-permute with additional states, dubbed frTtP+, can indeed attain security when operated under a suitable feedback function and properly initialized additional state. To be precise, we prove that frTtP+ provides security as long as D ≪ 2 s / 2 and T ≪ 2 s , where s denotes the size of the auxiliary state in terms of bits. To demonstrate the applicability of this result, we show that the construction O R A N G E - Z E S T mod belongs to this class, thereby obtaining the desired security. In addition, we propose a family of full rate Transform-then-permute construction with Beetle like feedback function, dubbed fr-Beetle, which also achieves the same level of security.
In CRYPTO 2011, Yasuda proposed a variable input-length PRF based on an n-bit block cipher, called PMAC Plus. PMAC Plus is a rate-1 construction and inherits the well-known PMAC parallel network with a low additional cost. However, unlike PMAC, PMAC Plus is secure roughly up to 22n/3 queries. Later in CRYPTO 2018, Leurent et al., and then Lee et al. in EUROCRYPT 2020 established a tight security bound of 23n/4 on PMAC Plus. In this paper, we propose a public permutation-based variable input-length PRF called pPMAC Plus. We show that pPMAC Plus is secure against all adversaries that make at most 22n/3 queries. We also show that the bound is essentially tight. It is of note here that instantiation of each block cipher of PMAC Plus with the two-round iterated Even-Mansour cipher can yield a beyond-birthday-secure PRF based on public permutations. Altogether, the solution incurs (2l + 4) permutation calls, whereas our proposal requires only (l + 2) permutation calls, l being the maximum number of message blocks.
Liskov, Rivest and Wagner laid the theoretical foundations for tweakable block ciphers (TBC). In a seminal paper, they proposed two (up to) birthday-bound secure design strategies — LRW1 and LRW2 — to convert any block cipher into a TBC. Several of the follow-up works consider cascading of LRW-type TBCs to construct beyond-the-birthday bound (BBB) secure TBCs. Landecker et al. demonstrated that just two-round cascading of LRW2 can already give a BBB security. Bao et al. undertook a similar exercise in context of LRW1 with TNT — a three-round cascading of LRW1 — that has been shown to achieve BBB security as well. In this paper, we present a CCA distinguisher on TNT that achieves a non-negligible advantage with O(2^n/2) queries, directly contradicting the security claims made by the designers. We provide a rigorous and complete advantage calculation coupled with experimental verification that further support our claim. Next, we provide new and simple proofs of birthday-bound CCA security for both TNT and its single-key variant, which confirm the tightness of our attack. Furthering on to a more positive note, we show that adding just one more block cipher call, referred as 4- , does not just re-establish the BBB security, but also amplifies it up to 2^3n/4 queries. As a side-effect of this endeavour, we propose a new abstraction of the cascaded LRW-design philosophy, referred to as the LRW+ paradigm, comprising two block cipher calls sandwiched between a pair of tweakable universal hashes. This helps us to provide a modular proof covering all cascaded LRW constructions with at least 2 rounds, including 4- , and its more established relative, the well-known CLRW2, or more aptly, 2- .
Wonil Lee合作论文数Samsung Electronic Ltd7