149 lines
4.8 KiB
Markdown
149 lines
4.8 KiB
Markdown
# Data Encryption Standard (DES)
|
||
|
||
### Pseudorandom Permutations
|
||
|
||
- A pseudorandom permutation is a function that cannot be distinguished from a random permutation
|
||
- Maps a set of values $\{0,1\}^n \times \{0,1\}^s \rightarrow \{0,1\}^n$ such that:
|
||
- For any key, the function F is a *bijection* (1:1)
|
||
- The key just changes the mapping
|
||
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
|
||
|
||

|
||
|
||
**Confusion**: Obscure the relationship between plaintext, key and ciphertext
|
||
|
||
- Often achieved through substitution operations
|
||
- Using lookup tables
|
||
|
||
**Diffusion**: Influence of each plaintext and key bit is distributed throughout the ciphertext
|
||
|
||
- Achieved via permutation
|
||
- Swapping or otherwise mixing bits/bytes
|
||
|
||
Shannon called a cipher like this a **product cipher**
|
||
|
||
### Feistel Network
|
||
|
||
- A Feistel network is one mechanism used to create block ciphers
|
||
- Developed by Horst Feistel while he worked at IBM
|
||
- Underpins DES, GOST, Blowfish, Twofish and numerous others.
|
||
|
||

|
||
|
||
- To decrypt, we run the encrypted bits through the network again
|
||
|
||
##### A Single Feistel Round
|
||
|
||
- During each round, only half of the block is encrypted
|
||
|
||

|
||
|
||
Very similar to a stream cipher.
|
||
|
||
###### Round $i$
|
||
|
||

|
||
|
||
###### Round $i+1$
|
||
|
||

|
||
|
||
Note - the last round does a final swap so the left and right are in the correct places.
|
||
|
||
###### Decrypting
|
||
|
||

|
||
|
||

|
||
|
||
Basically the `xor`s cancel themselves out, the most important part is choosing a good function $f$
|
||
|
||
#### About Feistel Networks
|
||
|
||
- 1 or 2 rounds are not sufficient
|
||
- Luby and Rackoff show that if $f$ is a cryptographically secure pseudorandom function then:
|
||
- 3 rounds are sufficient to make a pseudorandom permutation
|
||
- 4 rounds are sufficient to make a strong pseudorandom permutation
|
||
- Balanced Feistel networks
|
||
- L and R are equal sizes
|
||
- Unbalanced Feistel networks
|
||
- L and R can be different sizes
|
||
- e.g. `skipjack`, `OAEP`
|
||
|
||
### DES
|
||
|
||
1972: NIST put out a call for a US standard for encryption
|
||
|
||
1974: IBM propose DES
|
||
|
||
1976: NIST accepts an altered version of DES following consultation with NSA
|
||
|
||
- Feistel network with 64-bit block size
|
||
- 56-bit key
|
||
- The most studied cipher in history
|
||
- Hasn’t been broken for over 46 years
|
||
|
||

|
||
|
||

|
||
|
||
This speeds up loading bits into registers
|
||
|
||
##### The F function
|
||
|
||

|
||
|
||
$S_1, S_2....$ are called s-boxes. These substitute 6-bit inputs with 4-bit outputs based on lookup tables. The lookup tables for each s-box are different.
|
||
|
||
##### Expansion
|
||
|
||
- Adds *diffusion*
|
||
- Increases from 32 to 48 bits to match the round key
|
||
|
||

|
||
|
||
> Half the input bits are connected to two output positions
|
||
|
||
##### Substitution Boxes
|
||
|
||
- Add confusion
|
||
- The s-boxes map 6-bit inputs to 4-bit outputs
|
||
- There are 8 s-boxes in total, each is different
|
||
|
||

|
||
|
||
- This s-box is not random, very carefully designed
|
||
- s-boxes need to be highly **non-linear**: $S(a) \oplus S(b) \neq S(a\oplus b)$
|
||
- This prevents simple systems of linear equations such as we saw in LFSRs.
|
||
- The formula needed to represent DES is too complicated
|
||
- Key design principles
|
||
1. No output bit should be too close to a linear combination of input bits
|
||
2. 1-bit change input should lead to at least 2-bits output
|
||
3. If you only change the 4 middle bits, each output must occur exactly once
|
||
4. If the first two bits are different but the last two are identical, the output must differ
|
||
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
|
||
- We want to limit the number of predictable swaps
|
||
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
|
||
|
||
##### Permutation
|
||
|
||
- At the end of $f()$ is a permutation
|
||
- This moves bits between s-boxes on the next round
|
||
|
||

|
||
|
||
- Blue showing how $S_1$ output bits are diffused
|
||
|
||
#### The Avalanche Effect
|
||
|
||
If you input all 0s, we will see a random cipher text
|
||
|
||
However, if we change one 0 to a 1, how does this affect the result?
|
||
|
||
- On average, if you change one (first) bit in $R$, one bit will change in the expansion
|
||
- Due to the way the s-boxes are set up, at least 2 of the 4 bits in the output will be different
|
||
- Now when the permutation happens, these two changes are spread to other s-boxes
|
||
- Now next round we’ll get 4 changes, then 8, then 16 …
|
||
|
||
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.
|