<p>Key committing security is a crucial metric of authentication encryption schemes, complementing the fundamental principles of confidentiality and integrity. It ensures that an adversary cannot decrypt a given ciphertext to different sets of key, nonce, and associated data. In this study, we explore a key committing attack on the authenticated encryption stream cipher Tiaoxin-346 from the perspective of internal state collisions. We establish a more rigorous constraint within the FROB framework by identifying a different settings of <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq1.gif" Format="GIF" Height="19" Rendition="HTML" Resolution="72" Type="Linedraw" Width="126" /> </InlineMediaObject> <EquationSource Format="TEX">\(\left( k_{2}, Nonce, AD^{*}\right)\)</EquationSource> <EquationSource Format="MATHML"><math> <mfenced close=")" open="("> <msub> <mi>k</mi> <mn>2</mn> </msub> <mo>,</mo> <mi>N</mi> <mi>o</mi> <mi>n</mi> <mi>c</mi> <mi>e</mi> <mo>,</mo> <mi>A</mi> <mmultiscripts> <mi>D</mi> <mrow /> <mrow> <mrow /> <mo>∗</mo> </mrow> </mmultiscripts> </mfenced> </math></EquationSource> </InlineEquation> for any specified <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq2.gif" Format="GIF" Height="19" Rendition="HTML" Resolution="72" Type="Linedraw" Width="126" /> </InlineMediaObject> <EquationSource Format="TEX">\(\left( k_{1}, Nonce, AD_{1}\right)\)</EquationSource> <EquationSource Format="MATHML"><math> <mfenced close=")" open="("> <msub> <mi>k</mi> <mn>1</mn> </msub> <mo>,</mo> <mi>N</mi> <mi>o</mi> <mi>n</mi> <mi>c</mi> <mi>e</mi> <mo>,</mo> <mi>A</mi> <msub> <mi>D</mi> <mn>1</mn> </msub> </mfenced> </math></EquationSource> </InlineEquation>. Specifically, we demonstrate that for the Tiaoxin-346 algorithm, it is possible to find another settings of key <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq3.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="16" /> </InlineMediaObject> <EquationSource Format="TEX">\(k_{2}\)</EquationSource> <EquationSource Format="MATHML"><math> <msub> <mi>k</mi> <mn>2</mn> </msub> </math></EquationSource> </InlineEquation> and associated data <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq4.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(AD^{*}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>A</mi> <mmultiscripts> <mi>D</mi> <mrow /> <mrow> <mrow /> <mo>∗</mo> </mrow> </mmultiscripts> </mrow> </math></EquationSource> </InlineEquation> with a computational complexity of <i>O</i>(1), given any key <InlineEquation ID="IEq5"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq5.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="16" /> </InlineMediaObject> <EquationSource Format="TEX">\(k_{1}\)</EquationSource> <EquationSource Format="MATHML"><math> <msub> <mi>k</mi> <mn>1</mn> </msub> </math></EquationSource> </InlineEquation> and <InlineEquation ID="IEq6"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq6.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="34" /> </InlineMediaObject> <EquationSource Format="TEX">\(AD_{1}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>A</mi> <msub> <mi>D</mi> <mn>1</mn> </msub> </mrow> </math></EquationSource> </InlineEquation>. We provide a detailed explanation of the rationale and a step-by-step methodology for constructing an internal state collision at the seventh round of the update process, aimed at recovering the appropriate <InlineEquation ID="IEq7"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq7.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(AD^{*}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>A</mi> <mmultiscripts> <mi>D</mi> <mrow /> <mrow> <mrow /> <mo>∗</mo> </mrow> </mmultiscripts> </mrow> </math></EquationSource> </InlineEquation>. Notably, the computational complexity of our attack is <i>O</i>(1), significantly lower than the generic attack complexity of <InlineEquation ID="IEq8"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42400_2024_331_Article_IEq8.gif" Format="GIF" Height="23" Rendition="HTML" Resolution="72" Type="Linedraw" Width="54" /> </InlineMediaObject> <EquationSource Format="TEX">\(O\left( 2^{64}\right)\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>O</mi> <mfenced close=")" open="("> <msup> <mn>2</mn> <mn>64</mn> </msup> </mfenced> </mrow> </math></EquationSource> </InlineEquation>, which effectively violates the key commitment security of Tiaoxin-346. The results of this study contribute to refining the security of authenticated encryption algorithms and offer valuable insights for the design of round update functions in AES-based schemes.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Key committing attack on Tiaoxin-346 algorithm

  • Nan Liu,
  • Chenhui Jin,
  • Junwei Yu

摘要

Key committing security is a crucial metric of authentication encryption schemes, complementing the fundamental principles of confidentiality and integrity. It ensures that an adversary cannot decrypt a given ciphertext to different sets of key, nonce, and associated data. In this study, we explore a key committing attack on the authenticated encryption stream cipher Tiaoxin-346 from the perspective of internal state collisions. We establish a more rigorous constraint within the FROB framework by identifying a different settings of \(\left( k_{2}, Nonce, AD^{*}\right)\) k 2 , N o n c e , A D for any specified \(\left( k_{1}, Nonce, AD_{1}\right)\) k 1 , N o n c e , A D 1 . Specifically, we demonstrate that for the Tiaoxin-346 algorithm, it is possible to find another settings of key \(k_{2}\) k 2 and associated data \(AD^{*}\) A D with a computational complexity of O(1), given any key \(k_{1}\) k 1 and \(AD_{1}\) A D 1 . We provide a detailed explanation of the rationale and a step-by-step methodology for constructing an internal state collision at the seventh round of the update process, aimed at recovering the appropriate \(AD^{*}\) A D . Notably, the computational complexity of our attack is O(1), significantly lower than the generic attack complexity of \(O\left( 2^{64}\right)\) O 2 64 , which effectively violates the key commitment security of Tiaoxin-346. The results of this study contribute to refining the security of authenticated encryption algorithms and offer valuable insights for the design of round update functions in AES-based schemes.