arrow
返回

Plaintext recovery and tag guessing attacks on authenticated encryption algorithm COLM

delete2022-11-01
delete1
PRE
AI
S
Sırrı Erdem Ulusoy *
O
Orhun Kara
M
Mehmet Önder Efe
DOI:10.1016/j.jisa.2022.103342delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
There are three main approaches related to cryptanalysis of Authenticated Encryption with Associated Data (AEAD) algorithms: Simulating the encryption oracle (universal forgery attack), simulating the decryption oracle (plaintext recovery attack) and producing the valid tag of a given ciphertext (tag guessing attack). In this work, we analyze the security of COLM in these approaches. COLM is one of the AEAD algorithms chosen in the final portfolio for defense-in-depth use case of the CAESAR competition. The ciphers in this portfolio are supposed to provide robust security with their multiple layered defense mechanisms. The main motivation of this work is to examine if COLM indeed satisfies defense-in-depth security. We make cryptanalysis of COLM, particularly in the chosen ciphertext attack (CCA) scenario, once its secret whitening parameter L = EK(0) is recovered. To the best of our knowledge, we give the first example of querying an EME/EMD (Encrypt-linearMix-Encrypt/Decrypt) AEAD scheme in its decryption direction for arbitrary ciphertexts, not produced previously by the oracle, namely either a forgery or tag guessing attack. We construct SEBC/SDBC (Simulation models of the Encryption/Decryption oracles of the underlying Block Cipher) of COLM, thereby forming the first examples of these models of an authenticated EME scheme simultaneously. The combination of our SEBC/SDBC is a powerful tool to mount a universal forgery attack, a tag guessing attack and a plaintext recovery attack. All of these attacks have polynomial time complexities once L is recovered in the offline phase, indicating that the security of COLM against plaintext recovery and tag guessing attacks is limited by the birthday bound. Apart from exploiting SEBC/SDBC, we mount a pair of plaintext recovery attacks and another universal forgery attack. Finally, we make some suggestions to prevent our attacks.
Keyword:
COLM
CAESAR competition
Authenticated encryption with associated data
AEAD
Universal forgery
Tag guessing
Plaintext recovery
Key recovery
AES
Biclique
Impossible differential
Meet-in-the-middle
SEBC
SDBC

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

H
Hacettepe University
学者数:
1.2W
论文数: 1.0W
被引数: 11
T
turkiye bilimsel ve teknolojik arastirma kurumu (tubitak)
学者数:
1.4K
论文数: 1.3K
被引数: 3
引用论文

引用论文

DPA Protected Implementation of OCB and COLM Authenticated Ciphers
err2019-01-01
err4
errOAAI
errJahanbani, Mohsen; Norozi, Zeinolabedin; Bagheri, Nasour
err分享
err收藏
ELmD: A Pipelineable Authenticated Encryption and Its Hardware Implementation
err2016-11-01
err29
PREAI
errBossuet, Lilian; Datta, Nilanjan; Mancillas-Lopez, Cuauhtemoc; Nandi, Mridul
err分享
err收藏
Lipoxygenase in the plant kingdom. I. Properties
err1992-08-30
err0
errOAAI
errL. C. Sanz; A. G. Pérez; J. M. Olías
err分享
err收藏