Files
notes/docs/lectures/cryptography/04_data_encryption.md
T

148 lines
4.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Data Encryption Standard (DES)
### Pseudorandom Permutations
- A pseudorandom permutation is a function that cannot be distinguished from a random permutation
- Maps a set of values $\{0,1\}^n \times \{0,1\}^s \rightarrow \{0,1\}^n$ such that:
- For any key, the function F is a *bijection* (1:1)
- The key just changes the mapping
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
![1645042514.png](img/1645042514.png)
**Confusion**: Obscure the relationship between plaintext, key and ciphertext
- Often achieved through substitution operations
- Using lookup tables
**Diffusion**: Influence of each plaintext and key bit is distributed throughout the ciphertext
- Achieved via permutation
- Swapping or otherwise mixing bits/bytes
Shannon called a cipher like this a **product cipher**
### Feistal Network
- A Feistal Network is one mechanism used to create block ciphers
- Developed by Horst Feistal while he worked at IBM
- Underpins DES, GOST, Blowfish, Twofish and numerous others.
![1645042957.png](img/1645042957.png)
- To decrypt, we run the encrypted bits through the network again
##### A Single Feistal Round
- During each round, only half of the block is encrypted
![1645043071.png](img/1645043071.png)
Very similar to a stream cipher.
###### Round $i$
![1645043210.png](img/1645043210.png)
###### Round $i+1$
![1645043312.png](img/1645043312.png)
Note - the last round does a final swap so the left and right are in the correct places.
###### Decrypting
![1645043479.png](img/1645043479.png)
![1645043523.png](img/1645043523.png)
Basically the `xor`s cancel themselves out, the most important part is choosing a good function $f$
#### About Feistal Networks
- 1 or 2 rounds is not sufficient
- Luby and Rackoff show that if $f$ is a cryptographically secure pseudorandom function then:
- 3 rounds are sufficient to make a pseudorandom permutation
- 4 rounds are sufficient to make a strong pseudorandom permutation
- Balanced Feistal networks
- L and R are equal sizes
- Unbalanced feistal networks
- L and R can be different sizes
- e.g. `skipjack`, `OAEP`
### DES
1972: NIST put out a call for a US standard for encryption
1974: IBM propose DES
1976: NIST accepts an altered version of DES following consultation with NSA
- Feistal network with 64-bit block size
- 56-bit key
- The most studied cipher in history
- Hasn’t been broken for over 46 years
![1645044034.png](img/1645044034.png)
![1645044122.png](img/1645044122.png)
This speeds up loading bits into registers
##### The F function
![1645044186.png](img/1645044186.png)
$S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits output based on lookup tables. The lookup tables for each s-box is different.
##### Expansion
- Adds *diffusion*
- Increases from 32 to 48 bits to match the round key
![1645044333.png](img/1645044333.png)
> Half the input bits are connected to two output positions
##### Substitution Boxes
- Add confusion
- The s-boxes map 6 bit inputs to 4-bit outputs
- There are 8 s-boxes in total, each is different
![1645044443.png](img/1645044443.png)
- This s-box is not random, very carefully designed
- s-boxes need to be highly **non-linear**: $S(a) \oplus S(b) \neq S(a\oplus b)$
- This prevents simple systems of linear equations such as we saw in LFSRs.
- The formula needed to represent DES is too complicated
- Key design principles
1. No output bit should be too close to a linear combination of input bits
2. 1-bit change input should lead to at least 2-bits output
3. If you only change the 4 middle bits, each output must occur exactly once
4. If the first two bits are different but the last two are identical, the output must differ
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
- We want to limit the number of predictable swaps
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
##### Permutation
- At the end of $f()$ is a permuatation
- This moves bits between s-boxes on the next round
![1645044919.png](img/1645044919.png)
- Blue showing how $S_1$ output bits are diffused
#### The Avalanche Effect
If you input all 0s, we will see a random cipher text
However if we change one 0 to a 1, how does this effect the result.
- On average, if you change one (first) bit in $R$, one bit will change in the expansion
- Due to the way the s-boxes are setup, at least 2 of the 4 bits in the output will be different
- Now when the permutation happens, these two changes are spread to other s-boxes
- Now next round we’ll get 4 changes, then 8, then 16 …
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.