Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -4,35 +4,35 @@
|
||||
|
||||
- A pseudorandom permutation is a function that cannot be distinguished from a random permutation
|
||||
- Maps a set of values $\{0,1\}^n \times \{0,1\}^s \rightarrow \{0,1\}^n$ such that:
|
||||
- For any key, the function F is a *bijection* (1:1)
|
||||
- The key just changes the mapping
|
||||
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
|
||||
- For any key, the function F is a *bijection* (1:1)
|
||||
- The key just changes the mapping
|
||||
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
|
||||
|
||||

|
||||
|
||||
**Confusion**: Obscure the relationship between plaintext, key and ciphertext
|
||||
|
||||
- Often achieved through substitution operations
|
||||
- Using lookup tables
|
||||
- Using lookup tables
|
||||
|
||||
**Diffusion**: Influence of each plaintext and key bit is distributed throughout the ciphertext
|
||||
|
||||
- Achieved via permutation
|
||||
- Swapping or otherwise mixing bits/bytes
|
||||
- Swapping or otherwise mixing bits/bytes
|
||||
|
||||
Shannon called a cipher like this a **product cipher**
|
||||
|
||||
### Feistal Network
|
||||
### Feistel Network
|
||||
|
||||
- A Feistal Network is one mechanism used to create block ciphers
|
||||
- Developed by Horst Feistal while he worked at IBM
|
||||
- A Feistel network is one mechanism used to create block ciphers
|
||||
- Developed by Horst Feistel while he worked at IBM
|
||||
- Underpins DES, GOST, Blowfish, Twofish and numerous others.
|
||||
|
||||

|
||||
|
||||
- To decrypt, we run the encrypted bits through the network again
|
||||
|
||||
##### A Single Feistal Round
|
||||
##### A Single Feistel Round
|
||||
|
||||
- During each round, only half of the block is encrypted
|
||||
|
||||
@@ -58,17 +58,17 @@ Note - the last round does a final swap so the left and right are in the correct
|
||||
|
||||
Basically the `xor`s cancel themselves out, the most important part is choosing a good function $f$
|
||||
|
||||
#### About Feistal Networks
|
||||
#### About Feistel Networks
|
||||
|
||||
- 1 or 2 rounds is not sufficient
|
||||
- 1 or 2 rounds are not sufficient
|
||||
- Luby and Rackoff show that if $f$ is a cryptographically secure pseudorandom function then:
|
||||
- 3 rounds are sufficient to make a pseudorandom permutation
|
||||
- 4 rounds are sufficient to make a strong pseudorandom permutation
|
||||
- Balanced Feistal networks
|
||||
- L and R are equal sizes
|
||||
- Unbalanced feistal networks
|
||||
- L and R can be different sizes
|
||||
- e.g. `skipjack`, `OAEP`
|
||||
- 3 rounds are sufficient to make a pseudorandom permutation
|
||||
- 4 rounds are sufficient to make a strong pseudorandom permutation
|
||||
- Balanced Feistel networks
|
||||
- L and R are equal sizes
|
||||
- Unbalanced Feistel networks
|
||||
- L and R can be different sizes
|
||||
- e.g. `skipjack`, `OAEP`
|
||||
|
||||
### DES
|
||||
|
||||
@@ -78,10 +78,10 @@ Basically the `xor`s cancel themselves out, the most important part is choosing
|
||||
|
||||
1976: NIST accepts an altered version of DES following consultation with NSA
|
||||
|
||||
- Feistal network with 64-bit block size
|
||||
- Feistel network with 64-bit block size
|
||||
- 56-bit key
|
||||
- The most studied cipher in history
|
||||
- Hasn’t been broken for over 46 years
|
||||
- Hasn’t been broken for over 46 years
|
||||
|
||||

|
||||
|
||||
@@ -93,7 +93,7 @@ This speeds up loading bits into registers
|
||||
|
||||

|
||||
|
||||
$S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits output based on lookup tables. The lookup tables for each s-box is different.
|
||||
$S_1, S_2....$ are called s-boxes. These substitute 6-bit inputs with 4-bit outputs based on lookup tables. The lookup tables for each s-box are different.
|
||||
|
||||
##### Expansion
|
||||
|
||||
@@ -107,7 +107,7 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
|
||||
##### Substitution Boxes
|
||||
|
||||
- Add confusion
|
||||
- The s-boxes map 6 bit inputs to 4-bit outputs
|
||||
- The s-boxes map 6-bit inputs to 4-bit outputs
|
||||
- There are 8 s-boxes in total, each is different
|
||||
|
||||

|
||||
@@ -115,19 +115,19 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
|
||||
- This s-box is not random, very carefully designed
|
||||
- s-boxes need to be highly **non-linear**: $S(a) \oplus S(b) \neq S(a\oplus b)$
|
||||
- This prevents simple systems of linear equations such as we saw in LFSRs.
|
||||
- The formula needed to represent DES is too complicated
|
||||
- The formula needed to represent DES is too complicated
|
||||
- Key design principles
|
||||
1. No output bit should be too close to a linear combination of input bits
|
||||
2. 1-bit change input should lead to at least 2-bits output
|
||||
3. If you only change the 4 middle bits, each output must occur exactly once
|
||||
4. If the first two bits are different but the last two are identical, the output must differ
|
||||
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
|
||||
- We want to limit the number of predictable swaps
|
||||
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
|
||||
1. No output bit should be too close to a linear combination of input bits
|
||||
2. 1-bit change input should lead to at least 2-bits output
|
||||
3. If you only change the 4 middle bits, each output must occur exactly once
|
||||
4. If the first two bits are different but the last two are identical, the output must differ
|
||||
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
|
||||
- We want to limit the number of predictable swaps
|
||||
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
|
||||
|
||||
##### Permutation
|
||||
|
||||
- At the end of $f()$ is a permuatation
|
||||
- At the end of $f()$ is a permutation
|
||||
- This moves bits between s-boxes on the next round
|
||||
|
||||

|
||||
@@ -138,11 +138,11 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
|
||||
|
||||
If you input all 0s, we will see a random cipher text
|
||||
|
||||
However if we change one 0 to a 1, how does this effect the result.
|
||||
However, if we change one 0 to a 1, how does this affect the result?
|
||||
|
||||
- On average, if you change one (first) bit in $R$, one bit will change in the expansion
|
||||
- Due to the way the s-boxes are setup, at least 2 of the 4 bits in the output will be different
|
||||
- Due to the way the s-boxes are set up, at least 2 of the 4 bits in the output will be different
|
||||
- Now when the permutation happens, these two changes are spread to other s-boxes
|
||||
- Now next round we’ll get 4 changes, then 8, then 16 …
|
||||
|
||||
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.
|
||||
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.
|
||||
Reference in new issue
Block a user