The Experts below are selected from a list of 13776 Experts worldwide ranked by ideXlab platform

Faiyaz Ahmad - One of the best experts on this subject based on the ideXlab platform.

  • cryptanalysis of image encryption based on permutation substitution using chaotic map and latin square image cipher
    FICTA (1), 2015
    Co-Authors: Musheer Ahmad, Faiyaz Ahmad
    Abstract:

    Recently Panduranga et al. suggested an image encryption algorithm based on permutation-substitution architecture using chaotic map and Latin square. According to the proposal, the pixels of plain-image are firstly scrambled according to permutation vector, extracted from chaotic sequence, in permutation phase. In substitution phase, the permuted image is substituted by XOR operation with key image generated from a keyed Latin square. The algorithm has the ability to adapt and encrypt any plain-image with unequal width and height. Moreover, it also exhibits the features of high entropy, low pixels correlation, large key space, high key sensitivity, etc. However, a careful analysis of Panduranga et al. algorithm unveils few security flaws which make it susceptible to Cryptographic Attack. In this paper, we analyze its security and proposed a chosen plaintext-Attack to break the algorithm completely. It is shown that the plain-image can be successfully recovered without knowing the secret key. The simulation of proposed Attack demonstrates that Panduranga et al. algorithm is not at all secure for practical encryption of sensitive digital images.

Musheer Ahmad - One of the best experts on this subject based on the ideXlab platform.

  • cryptanalysis of image encryption based on permutation substitution using chaotic map and latin square image cipher
    FICTA (1), 2015
    Co-Authors: Musheer Ahmad, Faiyaz Ahmad
    Abstract:

    Recently Panduranga et al. suggested an image encryption algorithm based on permutation-substitution architecture using chaotic map and Latin square. According to the proposal, the pixels of plain-image are firstly scrambled according to permutation vector, extracted from chaotic sequence, in permutation phase. In substitution phase, the permuted image is substituted by XOR operation with key image generated from a keyed Latin square. The algorithm has the ability to adapt and encrypt any plain-image with unequal width and height. Moreover, it also exhibits the features of high entropy, low pixels correlation, large key space, high key sensitivity, etc. However, a careful analysis of Panduranga et al. algorithm unveils few security flaws which make it susceptible to Cryptographic Attack. In this paper, we analyze its security and proposed a chosen plaintext-Attack to break the algorithm completely. It is shown that the plain-image can be successfully recovered without knowing the secret key. The simulation of proposed Attack demonstrates that Panduranga et al. algorithm is not at all secure for practical encryption of sensitive digital images.

Orumiehchiha, Mohammad Ali - One of the best experts on this subject based on the ideXlab platform.

  • Cryptanalysis of lightweight Cryptographic algorithms
    Sydney Australia : Macquarie University, 2014
    Co-Authors: Orumiehchiha, Mohammad Ali
    Abstract:

    Empirical thesis.Bibliography: pages 111-124.1. Introduction -- 2. Stream ciphers -- 3. Cryptanalysis of WG-7 stream cipher -- 4. Security evaluation of Rakaposhi stream cipher -- 5. Security analysis of linearly filtered NLFSRs -- 6. Practical Attack on NLM generators -- 7. Cryptanalysis of RC4(n,m) stream cipher -- 8. Cryptanalysis of a hash function based on RC4 -- 9. Conclusion.Stream ciphers are symmetric cipher systems which provide confidentiality in many applications ranging from mobile phone communication to virtual private networks. They may be implemented effciently in software and hardware and are a preferred choice when dealing with resource-constrained environments, such as smart cards, RFID tags,and sensor networks. This dissertation addresses cryptanalysis of several stream ciphers, and a hash function based on stream cipher. Also, the thesis investigates the design principles and security of stream ciphers built from nonlinear feedback shift registers. In a design view, any Cryptographic Attack shows a weak point in the design and immediately can be converted into an appropriate design criterion. Firstly, this thesis focuses on the WG-7, a lightweight stream cipher. It is shown that thekey stream generated by WG-7 can be distinguished from a random sequence with a negligible error probability. In addition, a key-recovery Attack on the cipher has been successfully proposed. Then, a security evaluation of the Rakaposhi stream cipher identifies weaknesses of the cipher. The main observation shows that the initialisation procedure has a sliding property. This property can be used to launch distinguishing and key-recovery Attacks. Further, the cipher is studied when the registers enter short cycles. In this case, the internal state can be recovered with less complexity than exhaustive search. New security features of a specific design based on nonlinear feedback shift registers have been explored. The idea applies a distinguishing Attack on linearly filtered nonlinear feedback shift registers. The Attack extends the idea on linear combinations of linearly filtered nonlinear feedback shift registers as well. The proposed Attacks allow the Attacker to mount linear Attacks to distinguish the output of the cipher and recover its internal state. The next topic analyses a new lightweight communication framework called NLM-MAC. Several critical Cryptographic weaknesses leading to key-recovery and forgery Attack have been indicated. It is shown that the adversary can recover the internal state of the NLM generator. The Attacker also is able to forge any MAC tag in real time. The proposed Attacks are completely practical and break the scheme. Another part demonstrates some new Cryptographic Attacks on RC4(n,m) stream cipher. The investigations have revealed several weaknesses of the cipher. Firstly, a distinguisher for the cipher is proposed. Secondly, a key-recovery Attack uses a method to find the secret key in real time. Finally, the RC4-BHF hash function that is based on the well-known RC4 stream cipher is analysed. Two Attacks on RC4-BHF have been developed. In the first Attack, the adversary is able to find collisions for two different messages. The second Attack shows how to design a distinguisher that can tell apart the sequence generated by RC4-BHF from a random one.Mode of access: World wide web1 online resource (xviii, 124 pages) table

R J F Cramer - One of the best experts on this subject based on the ideXlab platform.

  • cwi cryptanalyst discovers new Cryptographic Attack variant in flame spy malware
    2012
    Co-Authors: Marc Stevens, R J F Cramer
    Abstract:

    htmlabstractCryptanalyst Marc Stevens from the Centrum Wiskunde & Informatica (CWI) in Amsterdam, known for breaking the https security in 2008 using a cryptanalytic Attack on MD5, analyzed the recent Flame virus this week. He discovered that for this spy malware an as yet unknown Cryptographic Attack variant of his own MD5 Attack is used. Stevens analyzed this with new forensic software that he developed. Initially, the researcher assumed that Flame used his own Attack, which was made public in June 2009, but this was not the case. “Flame uses a completely new variant of a ‘chosen prefix collision Attack’ to impersonate a legitimate security update from Microsoft. The design of this new variant required world-class cryptanalysis,” says Marc Stevens. “It is very important to invest in Cryptographic research, to continue to be ahead of these developments in practice.”

Atanassov Latschesar - One of the best experts on this subject based on the ideXlab platform.

  • Online SPHINX: Ein Online-Passwortmanager, der gegen Offline-Attacken resistent ist.
    2019
    Co-Authors: Atanassov Latschesar
    Abstract:

    Diese Masterarbeit stellt den Online SPHINX Passwortmanager vor, der Domänenpasswörter aus dem Hauptpasswort, der Domäne und mehreren kryptografischen Schlüssel berechnet. Das Besondere an Online SPHINX ist, dass die kryptografischen Schlüssel auf dem Endgerät des Benutzers und einen oder mehreren Online SPHINX Webdiensten verteilt werden kann und dadurch Offline-Dictionary Attacken gegen das Hauptpasswort erschwert. Die prototypische Implementierung von Online SPHINX ist in der Funktionalität eingeschränkt und fokussiert sich auf die Registrierung, der Erstellung und dem Abfragen von Domänenpasswörter. Die Grundfunktionalität wurde umfangreich mit Unit, Integration und Benchmark Testfällen getestet und zeigt, dass Domänenpasswörter in weniger als eine Sekunde bei einer Schlüsselgröße von 3072 Bits berechnet werden können, abhängig von der Netzwerklatenz. Diese Arbeit ist in erster Linie praktisch orientiert. Auf eine kryptografische Sicherheitsanalyse der implementierten Protokolle wird nicht eingegangen.This master thesis introduces a new password manager called Online SPHINX that calculates the domain-specific passwords based on the master password, the domain name and several Cryptographic keys. These Cryptographic keys can be distributed among the users device and (a group of) one or several independent Online SPHINX services such that offline dictionary Attacks on the master password are mitigated. The prototype implementation of Online SPHINX covers only a subset of the use cases like the registration, password generation and retrieval process. The unit, integration and benchmark test results show that domain passwords are calculated deterministically within less than one second with a key length of 3072 bits depending on the network latency. This master thesis focuses primarily on the practical implementation. It is not in the scope of this master thesis to evaluate the Online SPHINX protocol against certain Cryptographic Attack models.vorgelegt von: Latschesar AtanassovWien, FH Campus Wien, Masterarb., 2019(VLID)343193