Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,155 @@
|
||||
# Data Encryption Standard
|
||||
|
||||
#### Key Schedule
|
||||
|
||||
- The **DES** key schedule simply returns various permutations of $k$ as sub-keys
|
||||
- $k_1, ... k_{16}$
|
||||
|
||||
##### PC-1
|
||||
|
||||
- Permutated Choice 1 (PC-1) selects 56 of the 64 bits
|
||||
- The other ‘parity’ bits are discarded: DES only uses a 56-bit key
|
||||
- Key bits are spread throughout the initial state of the key schedule
|
||||
- Key bits 8, 16, 24,…64 are not used
|
||||
|
||||

|
||||
|
||||
#### Left Rotation
|
||||
|
||||
- Left rotations (often written as `<<<`) represent a lift shift where the left most numbers wrap around to the right hand side
|
||||
- In DES, each 28-bit block is rotated left by `<<<1` for rounds 1,2,9,16 and `<<<2` otherwise
|
||||
- The total rotation is $4\cdot 1 + 12\cdot 2 = 28$ which means $C_0 = C_{16}$ and $D_0 = D_{16}$
|
||||
- NOTE: $C_0$ or $D_0$ is not used
|
||||
|
||||
##### PC-2
|
||||
|
||||
- Permuted Choice 2 select 48 of the 56 bits to be used as a round key
|
||||
|
||||

|
||||
|
||||
###### Properties of the Key Schedules
|
||||
|
||||
- Is entirely permutation based
|
||||
- Doesn’t use `xor`, addition or any other mixing operation
|
||||
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write seperate encrpt and decrypt functions
|
||||
- Usful for writing implementations on low memory devices (smart cards)
|
||||
|
||||
### Breaking DES
|
||||
|
||||
- DES has a key length of 56-bits
|
||||
- A brute force attack requires no knowledge of the cipher, only a pair $(x_0, y_0)$ of known plain and cipher text
|
||||
|
||||
$DES^{-1}k_i(y_0) = x_0$ for $i=0, 1, ... 2^{56}-1$
|
||||
|
||||
This would take minutes to hours on a cluster.
|
||||
|
||||
NOTE: $2^{56}-1$ is a very large number
|
||||
|
||||
#### Key Collisions
|
||||
|
||||
- For a 56-bit key but a 64-bit block is possible (though unlikely) a different key would work
|
||||
- How likely is this to happen for a 1 bit key and an $n$ bit block cipher
|
||||
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
|
||||
- $\frac{2^{64}}{2^{56}} = 2^8$
|
||||
|
||||

|
||||
|
||||
- DES was first brute forced in 1997 and is no longer secure
|
||||
|
||||

|
||||
|
||||
(days on y axis)
|
||||
|
||||
#### Double Encryption
|
||||
|
||||

|
||||
|
||||
- Naive brute fource suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
|
||||
- However using a meet-in-the middle attack this becomes trival.
|
||||
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
|
||||
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
|
||||
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
|
||||
|
||||

|
||||
|
||||
Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
|
||||
|
||||
- This is much better than brute force, but doesn’t make it easy
|
||||
- Trades off computation for storage - Petabytes for DES
|
||||
- Assumes some kind of $O(1)$ for $Z_{L,I}$
|
||||
|
||||
## 3DES
|
||||
|
||||
- Triple DES uses three different keys
|
||||
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
|
||||
- Often used in banking, smart cards and other payment systems
|
||||
|
||||

|
||||
|
||||
This prevents MITM attacks as one of the attacks will have to compute $2^{112}$ permutations
|
||||
|
||||
Why use `enc -> dec -> enc`?
|
||||
|
||||
This is for compatibility with legacy systems running DES.
|
||||
|
||||
This is why banking systems use 3DES as they already have the infrastructure for DES however 3DES is officially not recommended by NSA in 2016
|
||||
|
||||
## DES-X
|
||||
|
||||
- An alternative construction using a concept called **key-whitening**
|
||||
|
||||

|
||||
|
||||
- Theoretically this provides a seach space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
|
||||
- In practive securtity is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
|
||||
|
||||
# Cryptanalysis
|
||||
|
||||
#### What is a break?
|
||||
|
||||
- In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
|
||||
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
|
||||
- These are often academic breaks, rather than a practical security concern
|
||||
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
|
||||
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
|
||||
|
||||
##### Analytical Attacks
|
||||
|
||||
- Exploit some underlying structureal or mathematical weakness in a cipher
|
||||
- e.g. meet in the middle attack
|
||||
- Derivation of taps in LFSRs
|
||||
|
||||
##### Statistical Attacks
|
||||
|
||||
- Capture statistical patterns between input and output to recover key bits
|
||||
- Differential cryptanalysis
|
||||
- Linear cryptanalysis
|
||||
|
||||
###### Differential Cryptanalysis
|
||||
|
||||
- Different cryptanalysis is prehaps now the most important modern method for breaking block ciphers
|
||||
- It is a **chosen plaintext** attack
|
||||
- We aim to find predictable changes in output bits caused by known changes in the input bits
|
||||
|
||||

|
||||
|
||||
- Each of these s boxes has 4 bits, 16 possible values
|
||||
- This means any input change $\Delta x$ should cause some change $\Delta y$ with probability $p=1/16$
|
||||
- In a poor s-box, the likelihood might be much higher
|
||||
- The sum input change resulting in some output change $(\Delta x, \Delta y)$ is called a **differential** and has some probability of occurring
|
||||
|
||||

|
||||
|
||||
- Tracing differentials through a cipher provides us with **differential characteristics** e.g.
|
||||
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
|
||||
- These can be calculated by hand or using automated tools
|
||||
- The attack then looks for these expected differentials as you manipulate sub-key bits
|
||||
|
||||
###### Resisting differential cryptanalysis
|
||||
|
||||
- S-boxes must be designed such that the probability of any pair $(\Delta x, \Delta y)$ is as low as possible
|
||||
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
|
||||
- This is because AES has such good diffusion
|
||||
- More rounds make differentials even less likely
|
||||
- Good permuation to involve more s-boxes is vital
|
||||
- DES was specifically designed to resist this kind of attack
|
||||
Reference in new issue
Block a user