5.8 KiB
5.8 KiB
Data Encryption Standard
Key Schedule
- The DES key schedule simply returns various permutations of
kas sub-keysk_1, ... k_{16}
PC-1
- Permutated Choice 1 (PC-1) selects 56 of the 64 bits
- The other ‘parity’ bits are discarded: DES only uses a 56-bit key
- Key bits are spread throughout the initial state of the key schedule
- Key bits 8, 16, 24,…64 are not used
Left Rotation
- Left rotations (often written as
<<<) represent a lift shift where the left most numbers wrap around to the right hand side - In DES, each 28-bit block is rotated left by
<<<1for rounds 1,2,9,16 and<<<2otherwise - The total rotation is
4\cdot 1 + 12\cdot 2 = 28which meansC_0 = C_{16}andD_0 = D_{16}- NOTE:
C_0orD_0is not used
- NOTE:
PC-2
- Permuted Choice 2 select 48 of the 56 bits to be used as a round key
Properties of the Key Schedules
- Is entirely permutation based
- Doesn’t use
xor, addition or any other mixing operation - Because
C_0 = C_{16}andD_0 = D_{16}we don’t need to write seperate encrpt and decrypt functions- Usful for writing implementations on low memory devices (smart cards)
Breaking DES
- DES has a key length of 56-bits
- A brute force attack requires no knowledge of the cipher, only a pair
(x_0, y_0)of known plain and cipher text
DES^{-1}k_i(y_0) = x_0 for i=0, 1, ... 2^{56}-1
This would take minutes to hours on a cluster.
NOTE: 2^{56}-1 is a very large number
Key Collisions
- For a 56-bit key but a 64-bit block is possible (though unlikely) a different key would work
- How likely is this to happen for a 1 bit key and an
nbit block cipher\frac{2^l}{2^n}wherelis the length of the block andnis the key length\frac{2^{64}}{2^{56}} = 2^8
- DES was first brute forced in 1997 and is no longer secure
(days on y axis)
Double Encryption
- Naive brute fource suggests
2^{56}\cdot 2^{56} = 2^{112}keyspace - However using a meet-in-the middle attack this becomes trival.
- Step 1: Calculate encryptions of
x_1for allk_{1...,i}and store intermediate valuesZ_{1..,i} - Step 2: Calculate all decryptions of
y_1for allk_{R, j}to findZ_{R,i} - Step 3: Find any value of
Z_{R,j}matching existingZ_L,i
- Step 1: Calculate encryptions of
Meet-in-the-middle requires 2^{k+1} attemps rather than 2^{k\cdot 2}
- This is much better than brute force, but doesn’t make it easy
- Trades off computation for storage - Petabytes for DES
- Assumes some kind of
O(1)forZ_{L,I}
3DES
- Triple DES uses three different keys
- Either
enc -> enc -> encorenc -> dec -> enc
- Either
- Often used in banking, smart cards and other payment systems
This prevents MITM attacks as one of the attacks will have to compute 2^{112} permutations
Why use enc -> dec -> enc?
This is for compatibility with legacy systems running DES.
This is why banking systems use 3DES as they already have the infrastructure for DES however 3DES is officially not recommended by NSA in 2016
DES-X
- An alternative construction using a concept called key-whitening
- Theoretically this provides a seach space of
2^{k+2n}but meet-in-the-middle can be used here, as well as other more advanced attacks - In practive securtity is
2^{k+n-m}where an attack has2^mknown plain texts
Cryptanalysis
What is a break?
- In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
- For example, differential cryptanalysis requires
2^{47}operations on DES rather than2^{56}
- For example, differential cryptanalysis requires
- These are often academic breaks, rather than a practical security concern
- For example there is a related key attack on AES of
2^{99.5}, compared to brute force of2^{128} - Remember that a
2^{n-1}takes half the time2^ndoes
- For example there is a related key attack on AES of
Analytical Attacks
- Exploit some underlying structureal or mathematical weakness in a cipher
- e.g. meet in the middle attack
- Derivation of taps in LFSRs
Statistical Attacks
- Capture statistical patterns between input and output to recover key bits
- Differential cryptanalysis
- Linear cryptanalysis
Differential Cryptanalysis
- Different cryptanalysis is prehaps now the most important modern method for breaking block ciphers
- It is a chosen plaintext attack
- We aim to find predictable changes in output bits caused by known changes in the input bits
- Each of these s boxes has 4 bits, 16 possible values
- This means any input change
\Delta xshould cause some change\Delta ywith probabilityp=1/16 - In a poor s-box, the likelihood might be much higher
- The sum input change resulting in some output change
(\Delta x, \Delta y)is called a differential and has some probability of occurring
- Tracing differentials through a cipher provides us with differential characteristics e.g.
(\Delta x, \Delta y) =(0x80, 0xA0) wherep \geq 2^{-3} = 1/8
- These can be calculated by hand or using automated tools
- The attack then looks for these expected differentials as you manipulate sub-key bits
Resisting differential cryptanalysis
- S-boxes must be designed such that the probability of any pair
(\Delta x, \Delta y)is as low as possible- AES has a maximum likelihood of a differential per s-box of
2^{-6} - This is because AES has such good diffusion
- AES has a maximum likelihood of a differential per s-box of
- More rounds make differentials even less likely
- Good permuation to involve more s-boxes is vital
- DES was specifically designed to resist this kind of attack









