通过组合实现安全性放大:双重迭代理想密码的情形
密码学与安全
2007-05-23 v1
摘要
我们在香农模型中研究双重DES和(双密钥)三重DES对应构造的安全性。即,我们考虑F_{k1}(F_{k2}(.))和F_{k1}(F_{k2}^{-1}(F_{k1}(.))),其中组件函数是理想密码。这模拟了这些构造对“通用”攻击(如中间相遇攻击)的抵抗力。我们获得了首个证明,表明组合在某些有意义的意义上实际上提高了这些构造的安全性。我们计算了破解双重密码的概率上界,作为基础密码计算次数和所见组合密码示例数的函数,并表明成功概率是单密钥密码的平方。相同的界也适用于双密钥三重密码。第一个界是紧的,表明中间相遇攻击是针对双重密码的最佳可能通用攻击。
引用
@article{arxiv.cs/9809031,
title = {Security amplification by composition: The case of doubly-iterated, ideal ciphers},
author = {William Aiello and Mihir Bellare and Giovanni Di Crescenzo and Ramarathnam Venkatesan},
journal= {arXiv preprint arXiv:cs/9809031},
year = {2007}
}
备注
An extended abstract of this paper appeared in the proceedings of Crypto 98 conference (Springer Verlag LNCS Vol 1462, 1998). This is the full version