Another look at XCB

被引:0
作者
Debrup Chakraborty
Vicente Hernandez-Jimenez
Palash Sarkar
机构
[1] CINVESTAV-IPN,Department of Computer Science
[2] Indian Statistical Institute,Applied Statistics Unit
来源
Cryptography and Communications | 2015年 / 7卷
关键词
Disk encryption; IEEE-std 1619.2 2010; Wide block modes; Tweakable enciphering schemes; XCB; Data Encryption 68P25; Cryptography 94A60;
D O I
暂无
中图分类号
学科分类号
摘要
XCB is a tweakable enciphering scheme (TES) which was first proposed in 2004. The scheme was modified in 2007. We call these two versions of XCB as XCBv1 and XCBv2 respectively. XCBv2 was later proposed as a standard for encryption of sector oriented storage media in IEEE-std 1619.2 2010. There is no known proof of security for XCBv1 but the authors provided a concrete security bound for XCBv2 and a “proof” justifying the bound. In this paper we show that XCBv2 is not secure as a TES by showing an easy distinguishing attack on it. For XCBv2 to be secure, the message space should contain only messages whose lengths are multiples of the block length of the block cipher. Even for such restricted message spaces, the bound that the authors claim is not justified. We show this by pointing out some errors in the proof. For XCBv2 on full block messages, we provide a new security analysis. The resulting bound that can be proved is much worse than what has been claimed by the authors. Further, we provide the first concrete security bound for XCBv1, which holds for all message lengths. In terms of known security bounds, both XCBv1 and XCBv2 are worse compared to existing alternative TESs.
引用
收藏
页码:439 / 468
页数:29
相关论文
共 6 条
  • [1] Chakraborty D(2008)HCH: A new tweakable enciphering scheme using the hash-counter-hash approach IEEE Trans. Inf. Theory 54 1683-1699
  • [2] Sarkar P(2010)Reconfigurable hardware implementations of tweakable enciphering schemes IEEE Trans. Comput. 59 1547-1561
  • [3] Mancillas-López C(2009)Efficient tweakable enciphering schemes from (block-wise) universal hash functions IEEE Trans on Inf Theory 55 4749-4760
  • [4] Chakraborty D(undefined)undefined undefined undefined undefined-undefined
  • [5] Rodríguez-Henríquez F(undefined)undefined undefined undefined undefined-undefined
  • [6] Sarkar P(undefined)undefined undefined undefined undefined-undefined