The Experts below are selected from a list of 252 Experts worldwide ranked by ideXlab platform

David Wagner - One of the best experts on this subject based on the ideXlab platform.

  • Tweakable Block Ciphers
    Journal of Cryptology, 2010
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    A common trend in applications of block ciphers over the past decades has been to employ block ciphers as one piece of a “mode of operation”—possibly, a way to make a secure symmetric-key cryptosystem, but more generally, any cryptographic application. Most of the time, these modes of operation use a wide variety of techniques to achieve a subgoal necessary for their main goal: instantiation of “essentially different” instances of the block cipher. We formalize a cryptographic primitive, the “tweakable block cipher.” Such a cipher has not only the usual inputs—message and cryptographic key—but also a third input, the “tweak.” The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our abstraction brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher “tweakable” is small, and (3) it is easier to design and prove the security of applications of block ciphers that need this variability using tweakable block ciphers.

  • CRYPTO - Tweakable Block Ciphers
    Advances in Cryptology — CRYPTO 2002, 2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the "tweakable block cipher." Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the "tweak." The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher "tweakable" is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

  • tweakable block ciphers
    International Cryptology Conference, 2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the "tweakable block cipher." Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the "tweak." The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher "tweakable" is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

  • Tweakable block ciphers - eScholarship
    2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the tweakable block cipher. Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the tweak. The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher tweakable is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

Moses Liskov - One of the best experts on this subject based on the ideXlab platform.

  • Tweakable Block Ciphers
    Journal of Cryptology, 2010
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    A common trend in applications of block ciphers over the past decades has been to employ block ciphers as one piece of a “mode of operation”—possibly, a way to make a secure symmetric-key cryptosystem, but more generally, any cryptographic application. Most of the time, these modes of operation use a wide variety of techniques to achieve a subgoal necessary for their main goal: instantiation of “essentially different” instances of the block cipher. We formalize a cryptographic primitive, the “tweakable block cipher.” Such a cipher has not only the usual inputs—message and cryptographic key—but also a third input, the “tweak.” The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our abstraction brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher “tweakable” is small, and (3) it is easier to design and prove the security of applications of block ciphers that need this variability using tweakable block ciphers.

  • CRYPTO - Tweakable Block Ciphers
    Advances in Cryptology — CRYPTO 2002, 2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the "tweakable block cipher." Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the "tweak." The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher "tweakable" is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

  • tweakable block ciphers
    International Cryptology Conference, 2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the "tweakable block cipher." Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the "tweak." The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher "tweakable" is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

  • Tweakable block ciphers - eScholarship
    2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the tweakable block cipher. Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the tweak. The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher tweakable is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

Ronald L. Rivest - One of the best experts on this subject based on the ideXlab platform.

  • Tweakable Block Ciphers
    Journal of Cryptology, 2010
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    A common trend in applications of block ciphers over the past decades has been to employ block ciphers as one piece of a “mode of operation”—possibly, a way to make a secure symmetric-key cryptosystem, but more generally, any cryptographic application. Most of the time, these modes of operation use a wide variety of techniques to achieve a subgoal necessary for their main goal: instantiation of “essentially different” instances of the block cipher. We formalize a cryptographic primitive, the “tweakable block cipher.” Such a cipher has not only the usual inputs—message and cryptographic key—but also a third input, the “tweak.” The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our abstraction brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher “tweakable” is small, and (3) it is easier to design and prove the security of applications of block ciphers that need this variability using tweakable block ciphers.

  • CRYPTO - Tweakable Block Ciphers
    Advances in Cryptology — CRYPTO 2002, 2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the "tweakable block cipher." Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the "tweak." The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher "tweakable" is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

  • tweakable block ciphers
    International Cryptology Conference, 2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the "tweakable block cipher." Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the "tweak." The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher "tweakable" is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

  • Tweakable block ciphers - eScholarship
    2002
    Co-Authors: Moses Liskov, Ronald L. Rivest, David Wagner
    Abstract:

    We propose a new cryptographic primitive, the tweakable block cipher. Such a cipher has not only the usual inputs - message and cryptographic key - but also a third input, the tweak. The tweak serves much the same purpose that an Initialization Vector does for CBC mode or that a nonce does for OCB mode. Our proposal thus brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher tweakable is small, and (3) it is easier to design and prove modes of operation based on tweakable block ciphers.

Stamatis Vassiliadis - One of the best experts on this subject based on the ideXlab platform.

  • SAMOS - Rescheduling for optimized SHA-1 calculation
    Lecture Notes in Computer Science, 2006
    Co-Authors: Ricardo Chaves, Georgi Kuzmanov, Leonel Sousa, Stamatis Vassiliadis
    Abstract:

    This paper proposes the rescheduling of the SHA-1 hash function operations on hardware implementations. The proposal is mapped on the Xilinx Virtex II Pro technology. The proposed rescheduling allows for a manipulation of the critical path in the SHA-1 function computation, facilitating the implementation of a more parallelized structure without an increase on the required hardware resources. Two cores have been developed, one that uses a constant Initialization Vector and a second one that allows for different Initialization Vectors (IV), in order to be used in HMAC and in the processing of fragmented messages. A hybrid software/hardware implementation is also proposed. Experimental results indicate a throughput of 1.4 Gbits/s requiring only 533 slices for a constant IV and 596 for an imputable IV. Comparisons to SHA-1 related art suggest improvements of the throughput/slice metric of 29% against the most recent commercial cores and 59% to the current academia proposals.

  • Rescheduling for optimized SHA-1 calculation
    Lecture Notes in Computer Science, 2006
    Co-Authors: Ricardo Chaves, Georgi Kuzmanov, Leonel Sousa, Stamatis Vassiliadis
    Abstract:

    This paper proposes the rescheduling of the SHA-1 hash function operations on hardware implementations. The proposal is mapped on the Xilinx Virtex II Pro technology. The proposed rescheduling allows for a manipulation of the critical path in the SHA-1 function computation, facilitating the implementation of a more parallelized structure without an increase on the required hardware resources. Two cores have been developed, one that uses a constant Initialization Vector and a second one that allows for different Initialization Vectors (IV), in order to be used in HMAC and in the processing of fragmented messages. A hybrid software/hardware implementation is also proposed. Experimental results indicate a throughput of 1.4 Gbits/s requiring only 533 slices for a constant IV and 596 for an imputable IV. Comparisons to SHA-1 related art suggest improvements of the throughput/slice metric of 29% against the most recent commercial cores and 59% to the current academia proposals.

Deepinder P Sidhu - One of the best experts on this subject based on the ideXlab platform.

  • Initialization Vector attacks on the ipsec protocol suite
    Workshops on Enabling Technologies: Infrastracture for Collaborative Enterprises, 2000
    Co-Authors: Christopher Mccubbin, Ali Aydin Selcuk, Deepinder P Sidhu
    Abstract:

    In this paper, we analyze the security of IPsec against a class of attacks known as the IV attacks, which are based on modifying the Initialization Vector (IV) of a CBC-encrypted packet during transmission. We show that IV attacks can be a serious threat for IPsec if IPsec is not used carefully. We also discuss the defense methods against these attacks.

  • WETICE - Initialization Vector attacks on the IPsec protocol suite
    Proceedings IEEE 9th International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WET ICE 2000), 1
    Co-Authors: Christopher Mccubbin, Ali Aydin Selcuk, Deepinder P Sidhu
    Abstract:

    In this paper, we analyze the security of IPsec against a class of attacks known as the IV attacks, which are based on modifying the Initialization Vector (IV) of a CBC-encrypted packet during transmission. We show that IV attacks can be a serious threat for IPsec if IPsec is not used carefully. We also discuss the defense methods against these attacks.