155 lines
5.8 KiB
Markdown
155 lines
5.8 KiB
Markdown
# Data Encryption Standard
|
||
|
||
#### Key Schedule
|
||
|
||
- The **DES** key schedule simply returns various permutations of $k$ as sub-keys
|
||
- $k_1, ... k_{16}$
|
||
|
||
##### PC-1
|
||
|
||
- Permutated Choice 1 (PC-1) selects 56 of the 64 bits
|
||
- The other ‘parity’ bits are discarded: DES only uses a 56-bit key
|
||
- Key bits are spread throughout the initial state of the key schedule
|
||
- Key bits 8, 16, 24,…64 are not used
|
||
|
||

|
||
|
||
#### Left Rotation
|
||
|
||
- Left rotations (often written as `<<<`) represent a lift shift where the left most numbers wrap around to the right hand side
|
||
- In DES, each 28-bit block is rotated left by `<<<1` for rounds 1,2,9,16 and `<<<2` otherwise
|
||
- The total rotation is $4\cdot 1 + 12\cdot 2 = 28$ which means $C_0 = C_{16}$ and $D_0 = D_{16}$
|
||
- NOTE: $C_0$ or $D_0$ is not used
|
||
|
||
##### PC-2
|
||
|
||
- Permuted Choice 2 select 48 of the 56 bits to be used as a round key
|
||
|
||

|
||
|
||
###### Properties of the Key Schedules
|
||
|
||
- Is entirely permutation based
|
||
- Doesn’t use `xor`, addition or any other mixing operation
|
||
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write seperate encrpt and decrypt functions
|
||
- Usful for writing implementations on low memory devices (smart cards)
|
||
|
||
### Breaking DES
|
||
|
||
- DES has a key length of 56-bits
|
||
- A brute force attack requires no knowledge of the cipher, only a pair $(x_0, y_0)$ of known plain and cipher text
|
||
|
||
$DES^{-1}k_i(y_0) = x_0$ for $i=0, 1, ... 2^{56}-1$
|
||
|
||
This would take minutes to hours on a cluster.
|
||
|
||
NOTE: $2^{56}-1$ is a very large number
|
||
|
||
#### Key Collisions
|
||
|
||
- For a 56-bit key but a 64-bit block is possible (though unlikely) a different key would work
|
||
- How likely is this to happen for a 1 bit key and an $n$ bit block cipher
|
||
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
|
||
- $\frac{2^{64}}{2^{56}} = 2^8$
|
||
|
||

|
||
|
||
- DES was first brute forced in 1997 and is no longer secure
|
||
|
||

|
||
|
||
(days on y axis)
|
||
|
||
#### Double Encryption
|
||
|
||

|
||
|
||
- Naive brute fource suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
|
||
- However using a meet-in-the middle attack this becomes trival.
|
||
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
|
||
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
|
||
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
|
||
|
||

|
||
|
||
Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
|
||
|
||
- This is much better than brute force, but doesn’t make it easy
|
||
- Trades off computation for storage - Petabytes for DES
|
||
- Assumes some kind of $O(1)$ for $Z_{L,I}$
|
||
|
||
## 3DES
|
||
|
||
- Triple DES uses three different keys
|
||
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
|
||
- Often used in banking, smart cards and other payment systems
|
||
|
||

|
||
|
||
This prevents MITM attacks as one of the attacks will have to compute $2^{112}$ permutations
|
||
|
||
Why use `enc -> dec -> enc`?
|
||
|
||
This is for compatibility with legacy systems running DES.
|
||
|
||
This is why banking systems use 3DES as they already have the infrastructure for DES however 3DES is officially not recommended by NSA in 2016
|
||
|
||
## DES-X
|
||
|
||
- An alternative construction using a concept called **key-whitening**
|
||
|
||

|
||
|
||
- Theoretically this provides a seach space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
|
||
- In practive securtity is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
|
||
|
||
# Cryptanalysis
|
||
|
||
#### What is a break?
|
||
|
||
- In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
|
||
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
|
||
- These are often academic breaks, rather than a practical security concern
|
||
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
|
||
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
|
||
|
||
##### Analytical Attacks
|
||
|
||
- Exploit some underlying structureal or mathematical weakness in a cipher
|
||
- e.g. meet in the middle attack
|
||
- Derivation of taps in LFSRs
|
||
|
||
##### Statistical Attacks
|
||
|
||
- Capture statistical patterns between input and output to recover key bits
|
||
- Differential cryptanalysis
|
||
- Linear cryptanalysis
|
||
|
||
###### Differential Cryptanalysis
|
||
|
||
- Different cryptanalysis is prehaps now the most important modern method for breaking block ciphers
|
||
- It is a **chosen plaintext** attack
|
||
- We aim to find predictable changes in output bits caused by known changes in the input bits
|
||
|
||

|
||
|
||
- Each of these s boxes has 4 bits, 16 possible values
|
||
- This means any input change $\Delta x$ should cause some change $\Delta y$ with probability $p=1/16$
|
||
- In a poor s-box, the likelihood might be much higher
|
||
- The sum input change resulting in some output change $(\Delta x, \Delta y)$ is called a **differential** and has some probability of occurring
|
||
|
||

|
||
|
||
- Tracing differentials through a cipher provides us with **differential characteristics** e.g.
|
||
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
|
||
- These can be calculated by hand or using automated tools
|
||
- The attack then looks for these expected differentials as you manipulate sub-key bits
|
||
|
||
###### Resisting differential cryptanalysis
|
||
|
||
- S-boxes must be designed such that the probability of any pair $(\Delta x, \Delta y)$ is as low as possible
|
||
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
|
||
- This is because AES has such good diffusion
|
||
- More rounds make differentials even less likely
|
||
- Good permuation to involve more s-boxes is vital
|
||
- DES was specifically designed to resist this kind of attack |