This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+33 -33
View File
@@ -3,11 +3,11 @@
#### Key Schedule
- The **DES** key schedule simply returns various permutations of $k$ as sub-keys
- $k_1, ... k_{16}$
- $k_1, ... k_{16}$
##### PC-1
- Permutated Choice 1 (PC-1) selects 56 of the 64 bits
- Permuted Choice 1 (PC-1) selects 56 of the 64 bits
- The other ‘parity’ bits are discarded: DES only uses a 56-bit key
- Key bits are spread throughout the initial state of the key schedule
- Key bits 8, 16, 24,…64 are not used
@@ -16,14 +16,14 @@
#### Left Rotation
- Left rotations (often written as `<<<`) represent a lift shift where the left most numbers wrap around to the right hand side
- Left rotations (often written as `<<<`) represent a left shift where the leftmost numbers wrap around to the right-hand side
- In DES, each 28-bit block is rotated left by `<<<1` for rounds 1,2,9,16 and `<<<2` otherwise
- The total rotation is $4\cdot 1 + 12\cdot 2 = 28$ which means $C_0 = C_{16}$ and $D_0 = D_{16}$
- NOTE: $C_0$ or $D_0$ is not used
- NOTE: $C_0$ or $D_0$ is not used
##### PC-2
- Permuted Choice 2 select 48 of the 56 bits to be used as a round key
- Permuted Choice 2 selects 48 of the 56 bits to be used as a round key
![1645476385.png](img/1645476385.png)
@@ -31,8 +31,8 @@
- Is entirely permutation based
- Doesn’t use `xor`, addition or any other mixing operation
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write seperate encrpt and decrypt functions
- Usful for writing implementations on low memory devices (smart cards)
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write separate encrypt and decrypt functions
- Useful for writing implementations on low-memory devices (smart cards)
### Breaking DES
@@ -47,10 +47,10 @@ NOTE: $2^{56}-1$ is a very large number
#### Key Collisions
- For a 56-bit key but a 64-bit block is possible (though unlikely) a different key would work
- For a 56-bit key but a 64-bit block, it is possible (though unlikely) that a different key would work
- How likely is this to happen for a 1 bit key and an $n$ bit block cipher
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
- $\frac{2^{64}}{2^{56}} = 2^8$
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
- $\frac{2^{64}}{2^{56}} = 2^8$
![1645477137.png](img/1645477137.png)
@@ -64,15 +64,15 @@ NOTE: $2^{56}-1$ is a very large number
![1645477338.png](img/1645477338.png)
- Naive brute fource suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
- However using a meet-in-the middle attack this becomes trival.
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
- Naive brute force suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
- However, using a meet-in-the-middle attack, this becomes trivial.
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
![1645477760.png](img/1645477760.png)
Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
Meet-in-the-middle requires $2^{k+1}$ attempts rather than $2^{k\cdot 2}$
- This is much better than brute force, but doesn’t make it easy
- Trades off computation for storage - Petabytes for DES
@@ -81,7 +81,7 @@ Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
## 3DES
- Triple DES uses three different keys
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
- Often used in banking, smart cards and other payment systems
![1645478048.png](img/1645478048.png)
@@ -100,34 +100,34 @@ This is why banking systems use 3DES as they already have the infrastructure for
![1645478296.png](img/1645478296.png)
- Theoretically this provides a seach space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
- In practive securtity is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
- Theoretically this provides a search space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
- In practice, security is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
# Cryptanalysis
#### What is a break?
- In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
- These are often academic breaks, rather than a practical security concern
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
##### Analytical Attacks
- Exploit some underlying structureal or mathematical weakness in a cipher
- e.g. meet in the middle attack
- Derivation of taps in LFSRs
- Exploit some underlying structural or mathematical weakness in a cipher
- e.g. meet in the middle attack
- Derivation of taps in LFSRs
##### Statistical Attacks
- Capture statistical patterns between input and output to recover key bits
- Differential cryptanalysis
- Linear cryptanalysis
- Differential cryptanalysis
- Linear cryptanalysis
###### Differential Cryptanalysis
- Different cryptanalysis is prehaps now the most important modern method for breaking block ciphers
- Differential cryptanalysis is perhaps now the most important modern method for breaking block ciphers
- It is a **chosen plaintext** attack
- We aim to find predictable changes in output bits caused by known changes in the input bits
@@ -141,15 +141,15 @@ This is why banking systems use 3DES as they already have the infrastructure for
![1645479256.png](img/1645479256.png)
- Tracing differentials through a cipher provides us with **differential characteristics** e.g.
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
- These can be calculated by hand or using automated tools
- The attack then looks for these expected differentials as you manipulate sub-key bits
###### Resisting differential cryptanalysis
- S-boxes must be designed such that the probability of any pair $(\Delta x, \Delta y)$ is as low as possible
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
- This is because AES has such good diffusion
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
- This is because AES has such good diffusion
- More rounds make differentials even less likely
- Good permuation to involve more s-boxes is vital
- DES was specifically designed to resist this kind of attack
- Good permutation to involve more s-boxes is vital
- DES was specifically designed to resist this kind of attack