Files
notes/docs/lectures/cryptography/05_des2.md
T

155 lines
5.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Data Encryption Standard
#### Key Schedule
- The **DES** key schedule simply returns various permutations of $k$ as sub-keys
- $k_1, ... k_{16}$
##### PC-1
- Permutated Choice 1 (PC-1) selects 56 of the 64 bits
- The other ‘parity’ bits are discarded: DES only uses a 56-bit key
- Key bits are spread throughout the initial state of the key schedule
- Key bits 8, 16, 24,…64 are not used
![1645476128.png](img/1645476128.png)
#### Left Rotation
- Left rotations (often written as `<<<`) represent a lift shift where the left most numbers wrap around to the right hand side
- In DES, each 28-bit block is rotated left by `<<<1` for rounds 1,2,9,16 and `<<<2` otherwise
- The total rotation is $4\cdot 1 + 12\cdot 2 = 28$ which means $C_0 = C_{16}$ and $D_0 = D_{16}$
- NOTE: $C_0$ or $D_0$ is not used
##### PC-2
- Permuted Choice 2 select 48 of the 56 bits to be used as a round key
![1645476385.png](img/1645476385.png)
###### Properties of the Key Schedules
- Is entirely permutation based
- Doesn’t use `xor`, addition or any other mixing operation
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write seperate encrpt and decrypt functions
- Usful for writing implementations on low memory devices (smart cards)
### Breaking DES
- DES has a key length of 56-bits
- A brute force attack requires no knowledge of the cipher, only a pair $(x_0, y_0)$ of known plain and cipher text
$DES^{-1}k_i(y_0) = x_0$ for $i=0, 1, ... 2^{56}-1$
This would take minutes to hours on a cluster.
NOTE: $2^{56}-1$ is a very large number
#### Key Collisions
- For a 56-bit key but a 64-bit block is possible (though unlikely) a different key would work
- How likely is this to happen for a 1 bit key and an $n$ bit block cipher
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
- $\frac{2^{64}}{2^{56}} = 2^8$
![1645477137.png](img/1645477137.png)
- DES was first brute forced in 1997 and is no longer secure
![1645477221.png](img/1645477221.png)
(days on y axis)
#### Double Encryption
![1645477338.png](img/1645477338.png)
- Naive brute fource suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
- However using a meet-in-the middle attack this becomes trival.
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
![1645477760.png](img/1645477760.png)
Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
- This is much better than brute force, but doesn’t make it easy
- Trades off computation for storage - Petabytes for DES
- Assumes some kind of $O(1)$ for $Z_{L,I}$
## 3DES
- Triple DES uses three different keys
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
- Often used in banking, smart cards and other payment systems
![1645478048.png](img/1645478048.png)
This prevents MITM attacks as one of the attacks will have to compute $2^{112}$ permutations
Why use `enc -> dec -> enc`?
This is for compatibility with legacy systems running DES.
This is why banking systems use 3DES as they already have the infrastructure for DES however 3DES is officially not recommended by NSA in 2016
## DES-X
- An alternative construction using a concept called **key-whitening**
![1645478296.png](img/1645478296.png)
- Theoretically this provides a seach space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
- In practive securtity is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
# Cryptanalysis
#### What is a break?
- In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
- These are often academic breaks, rather than a practical security concern
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
##### Analytical Attacks
- Exploit some underlying structureal or mathematical weakness in a cipher
- e.g. meet in the middle attack
- Derivation of taps in LFSRs
##### Statistical Attacks
- Capture statistical patterns between input and output to recover key bits
- Differential cryptanalysis
- Linear cryptanalysis
###### Differential Cryptanalysis
- Different cryptanalysis is prehaps now the most important modern method for breaking block ciphers
- It is a **chosen plaintext** attack
- We aim to find predictable changes in output bits caused by known changes in the input bits
![1645479017.png](img/1645479017.png)
- Each of these s boxes has 4 bits, 16 possible values
- This means any input change $\Delta x$ should cause some change $\Delta y$ with probability $p=1/16$
- In a poor s-box, the likelihood might be much higher
- The sum input change resulting in some output change $(\Delta x, \Delta y)$ is called a **differential** and has some probability of occurring
![1645479256.png](img/1645479256.png)
- Tracing differentials through a cipher provides us with **differential characteristics** e.g.
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
- These can be calculated by hand or using automated tools
- The attack then looks for these expected differentials as you manipulate sub-key bits
###### Resisting differential cryptanalysis
- S-boxes must be designed such that the probability of any pair $(\Delta x, \Delta y)$ is as low as possible
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
- This is because AES has such good diffusion
- More rounds make differentials even less likely
- Good permuation to involve more s-boxes is vital
- DES was specifically designed to resist this kind of attack