Back to Search
Start Over
Security of Hash-then-CBC Key Wrapping Revisited
- Source :
- IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences. :25-34
- Publication Year :
- 2013
- Publisher :
- Institute of Electronics, Information and Communications Engineers (IEICE), 2013.
-
Abstract
- Key wrapping schemes are used to encrypt data of high entropy, such as cryptographic keys. There are two known security definitions for key wrapping schemes. One captures the security against chosen plaintext attacks (called DAE-security), and the other captures known plaintext attacks (called AKW-security). In this paper, we revisit the security of Hash-then-CBC key wrapping schemes. At SKEW 2011, Osaki and Iwata showed that the U CC -then-CBC key wrapping scheme, a key wrapping scheme that uses the U CC hash function and the CBC mode, has provable AKW-security. In this paper, we show that the scheme achieves the stronger notion of DAE-security. We also show our proof in the variable input length setting, where the adversary is allowed making queries of varying lengths. To handle such a setting, we generalize the previous definition of the U CC hash function to the variable input length setting, and show an efficient construction that meets the definition. We next consider linear-then-CBC, 2nd-preimage-resistant-then-CBC, and universal-then-CBC schemes. At SAC 2009, Gennaro and Halevi noted that these schemes do not achieve DAE-security. However, details were not presented, and we show concrete and efficient chosen plaintext attacks on these schemes, and confirm that they do not achieve DAE-security.
- Subjects :
- Key Wrap
Theoretical computer science
Computer science
business.industry
Applied Mathematics
Distributed computing
Hash function
Skew
Plaintext
Data_CODINGANDINFORMATIONTHEORY
Encryption
Computer Graphics and Computer-Aided Design
Variable (computer science)
Mode (computer interface)
Known-plaintext attack
Signal Processing
Electrical and Electronic Engineering
business
Subjects
Details
- ISSN :
- 17451337 and 09168508
- Database :
- OpenAIRE
- Journal :
- IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences
- Accession number :
- edsair.doi...........3f4445f6aaf8eca07e2750b65399ed59