# Modern Stream Ciphers ### Pseudo-randomness - TRNGs - true Random Number Generator - Not feasible at scale - PRNGs - Pseudo Random Number Generator - CSPRNGs - Cryptographically Secure Pseudo Random Number Generator #### LFSRs - A Linear-feedback Shift Register us a register if buts whose positions shift to the right - Usually comprised of flip-flops, the last bit represents the output (Where the squares at the bottom are flip-flops) - If initialised to `000`, nothing happens as $0\oplus0 = 0$. - Therefore, we have $2^n-1$ states - Statistical randomness - To add more randomness to the setup, we can add another (more) `xor` gate - However, we have fewer states $$ s_m \equiv s_{m-1}p_{m-1} + ... + s_1p_1 + s_0p_0\space (mod \space 2)\\ s_{m+1} \equiv s_{m}p_{m-1} + ... + s_2p_1 + s_1p_0\space (mod \space 2) $$ - We usually represent m-bit LFSRs using polynomials of degree m. - In general $P(x)=x^m + p_{m-1}x^{m-1} + ... + p_1x + p_0$ - LFSRs that have primitive polynoimials produce sequences of maximum length - There are many and are easily computed - $x^5 + x^2 + 1$ has 31 states - $x^{10} + x^3 + 1$ has 1023 - $x^{85}+x^8+x^2+x+1$ has $10^{26}$ states ##### Attacking LFSRs Suppose an attacker knows $2m-1$ plain text bits **Step 1** Calculate key bits $s_i \equiv y_i + x_i \space (mod\space 2), i=0,1,...2_{m-1}$ **Step 2** Reconstruct the LFSR $s_m \equiv s_{m-1}p_{m-1} + ... + s_1p_1 + s_0p_0$ $s_{m+1} \equiv s_{m}p_{m-1} + ... + s_2p_1 + s_1p_0$ … $s_{2m+1} \equiv s_{2m-1}p_{m} + ... + s_mp_1 + s_{m-1}p_0$ #### Trivium - LFSRs are much more cryptographically secure if we combine more than one together in a non-linear way. Trivium is 3 LFSR in a row - Feedback between each with non-linear AND gates - Initialises the LFSR with an 80-bit key and 80-bit random value ### ChaCha20 - ChaCha is a stream cipher written by Daniel Berstein - A modification of a previous cipher, Salsa - Very lightweight, using only `add`, `xor` and rotate operations - One of two ciphers in `TLS 1.3` - Dashes represent bit length - Constants are not secret - The block number can skip to anywhere - Suppose someone skips ahead on a video stream, the cipher can skip unlike other synchronous stream ciphers - Works well on low power devices, due to simplicity of encryption - Once the input and the mixed words are added together it is hard to know what the starting thing was - e.g. what two numbers have i added to make 100 ChaCha performs **20** rounds - Alternates column and diagonal rounds - Each round is 4 quarter rounds #### Vulnerabilities - Stream ciphers like ChaCha give us *confidentiality*, but *not integrity* - Running a stream cipher by itself is not sufficient