http://cat.inist.fr/?aModele=afficheN&cpsidt=13473842
Titre du document / Document title
Cryptanalysis of the ANSI X9.52 CBCM mode
Auteur(s) / Author(s)
BIHAM Eli (1) ; KNUDSEN Lars R. (2) ;
Affiliation(s) du ou des auteurs / Author(s) Affiliation(s)
(1) Computer Science Department, Technion - Israel Institute of Technology, Haifa 32000, ISRAEL
(2) Department of Informatics, University of Bergen, Hi-techcenter, 5020 Bergen, NORVEGE
Résumé / Abstract
In this paper we cryptanalyze the CBCM mode of operation, which was almost included in the ANSI X9.52 Triple-DES Modes of Operation standard. The CBCM mode is a Triple-DES CBC variant which was designed against powerful attacks which control intermediate feedback for the benefit of the attacker. For this purpose, it uses intermediate feedbacks that the attacker cannot control, choosing them as a keyed OFB stream, independent of the plaintexts and the ciphertexts. In this paper we find a way to use even this kind of feedback for the benefit of the attacker, and we present an attack which requires a single chosen ciphertext of 2^65 blocks which needs to be stored and 2^59 complexity of analysis (CBCM encryptions) to find the key with a high probability. As a consequence of our attack, ANSI decided to remove the CBCM mode from the proposed standard.
Revue / Journal Title
Journal of cryptology ISSN 0933-2790
Source / Source
2002, vol. 15, no1, pp. 47-59 (25 ref.)
Langue / Language
Anglais
Editeur / Publisher
Springer, New York, NY, ETATS-UNIS (1988) (Revue)
Mots-clés anglais / English Keywords
Cryptanalysis ;
Mots-clés français / French Keywords
Mode CBCM ; Mode opération ; ANSI X9.52 ; Cryptanalyse ;
Mots-clés espagnols / Spanish Keywords
Criptoanálisis ;
Localisation / Location
INIST-CNRS, Cote INIST : 21877, 35400010228238.0030