Known-IV, Known-in-Advance-IV, and Replayed-and-Known-IV Attacks on Multiple Modes of Operation of Block Ciphers

Springer Science and Business Media LLC - Tập 19 - Trang 441-462 - 2006
Deukjo Hong1, Seokhie Hong1, Wonil Lee1, Sangjin Lee1, Jongin Lim1, Jaechul Sung2, Okyeon Yi3
1CIST, Korea University, Anam-dong, Seongbuk-gu, Seoul, 136-701, Korea
2Department of Mathematics, The University of Seoul, Jeonnong-dong, Dongdaemun-gu, Seoul, 130-743, Korea
3Department of Mathematics, Kookmin University, Jeongneung-dong, Seongbuk-gu, Seoul, 136-702, Korea

Tóm tắt

Normally, it has been believed that the initial values of cryptographic schemes do not need to be managed secretly unlike the secret keys. However, we show that multiple modes of operation of block ciphers can suffer a loss of security by the state of the initial values. We consider several attacks according to the environment of the initial values; known-IV attack, known-in-advance-IV attack, and replayed-and-known-IV attack. Our attacks on cascaded three-key triple modes of operation requires 3-7 blocks of plaintexts (or ciphertexts) and 3 · 256-9 · 256 encryptions. We also give the attacks on multiple modes proposed by Biham.