Cryptanalysis of multiple modes of operation

被引:13
作者
Biham, E [1 ]
机构
[1] Technion Israel Inst Technol, Dept Comp Sci, IL-32000 Haifa, Israel
关键词
block ciphers; modes of operation; multiple modes;
D O I
10.1007/s001459900034
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In recent years, several new attacks on DES were introduced. These attacks have led researchers to suggest stronger replacements for DES, and in particular new modes of operation for DES. The most popular new modes are triple DES variants, which are claimed to be as secure as triple DES. To speed up hardware implementations of these modes, and to increase the avalanche, many suggestions apply several standard modes sequentially. In this paper we study these multiple (cascade) modes of operation. This study shows that many multiple modes are much weaker than multiple DES, and their strength is theoretically comparable to a single DES. We conjecture that operation modes should be designed around an underlying cryptosystem without any attempt to use intermediate data as feedback, or to mix the feedback into an intermediate round. Thus, in particular, triple DES used in CBC mode is more secure than three single DESs used in triple CBC mode. Alternatively, if several encryptions are applied to each block, the best choice is to concatenate them to one long encryption, and build the mode of operation around it.
引用
收藏
页码:45 / 58
页数:14
相关论文
共 20 条
[1]  
[Anonymous], LECT NOTES COMPUTER
[2]  
Biham E., 1993, DIFFERENTIAL CRYPTAN
[3]  
BIHAM E, 1994, LECT NOTES COMPUTER, V950, P461
[4]  
Biham E., 1993, LNCS, V740, P487
[5]  
Biham E., 1995, LECT NOTES COMPUTER, V950, P341
[6]  
COPPERSMITH D, 1995, COMMUNICATION 0208
[7]  
DAVIES D, 1995, J CRYPTOL, V8, P1, DOI 10.1007/BF00204799
[8]  
DAVIES DW, 1987, COMMUNICATION
[9]   EXHAUSTIVE CRYPT-ANALYSIS OF NBS DATA ENCRYPTION STANDARD [J].
DIFFIE, W ;
HELLMAN, ME .
COMPUTER, 1977, 10 (06) :74-84
[10]  
Dobbertin Hans, 1996, LECT NOTES COMPUTER, V1039, P53