The Experts below are selected from a list of 19752 Experts worldwide ranked by ideXlab platform
Mihir Bellare - One of the best experts on this subject based on the ideXlab platform.
-
Mass Surveillance without the state strongly undetectable algorithm substitution attacks
Computer and Communications Security, 2015Co-Authors: Mihir Bellare, Joseph Jaeger, Daniel M KaneAbstract:We present new algorithm-substitution attacks (ASAs) on symmetric encryption that improve over prior ones in two ways. First, while prior attacks only broke a sub-class of randomized schemes having a property called coin injectivity, our attacks break ALL randomized schemes. Second, while prior attacks are stateful, ours are stateless, achieving a notion of strong undetectability that we formalize. Together this shows that ASAs are an even more dangerous and powerful Mass Surveillance method than previously thought. Our work serves to increase awareness about what is possible with ASAs and to spur the search for deterrents and counter-measures.
-
ACM Conference on Computer and Communications Security - Mass-Surveillance without the State: Strongly Undetectable Algorithm-Substitution Attacks
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015Co-Authors: Mihir Bellare, Joseph Jaeger, Daniel M KaneAbstract:We present new algorithm-substitution attacks (ASAs) on symmetric encryption that improve over prior ones in two ways. First, while prior attacks only broke a sub-class of randomized schemes having a property called coin injectivity, our attacks break ALL randomized schemes. Second, while prior attacks are stateful, ours are stateless, achieving a notion of strong undetectability that we formalize. Together this shows that ASAs are an even more dangerous and powerful Mass Surveillance method than previously thought. Our work serves to increase awareness about what is possible with ASAs and to spur the search for deterrents and counter-measures.
-
security of symmetric encryption against Mass Surveillance
International Cryptology Conference, 2014Co-Authors: Mihir Bellare, Kenneth G Paterson, Phillip RogawayAbstract:Motivated by revelations concerning population-wide Surveillance of encrypted communications, we formalize and investigate the resistance of symmetric encryption schemes to Mass Surveillance. The focus is on algorithm-substitution attacks (ASAs), where a subverted encryption algorithm replaces the real one. We assume that the goal of “big brother” is undetectable subversion, meaning that ciphertexts produced by the subverted encryption algorithm should reveal plaintexts to big brother yet be indistinguishable to users from those produced by the real encryption scheme. We formalize security notions to capture this goal and then offer both attacks and defenses. In the first category we show that successful (from the point of view of big brother) ASAs may be mounted on a large class of common symmetric encryption schemes. In the second category we show how to design symmetric encryption schemes that avoid such attacks and meet our notion of security. The lesson that emerges is the danger of choice: randomized, stateless schemes are subject to attack while deterministic, stateful ones are not.
-
CRYPTO (1) - Security of Symmetric Encryption against Mass Surveillance
Advances in Cryptology – CRYPTO 2014, 2014Co-Authors: Mihir Bellare, Kenneth G Paterson, Phillip RogawayAbstract:Motivated by revelations concerning population-wide Surveillance of encrypted communications, we formalize and investigate the resistance of symmetric encryption schemes to Mass Surveillance. The focus is on algorithm-substitution attacks (ASAs), where a subverted encryption algorithm replaces the real one. We assume that the goal of “big brother” is undetectable subversion, meaning that ciphertexts produced by the subverted encryption algorithm should reveal plaintexts to big brother yet be indistinguishable to users from those produced by the real encryption scheme. We formalize security notions to capture this goal and then offer both attacks and defenses. In the first category we show that successful (from the point of view of big brother) ASAs may be mounted on a large class of common symmetric encryption schemes. In the second category we show how to design symmetric encryption schemes that avoid such attacks and meet our notion of security. The lesson that emerges is the danger of choice: randomized, stateless schemes are subject to attack while deterministic, stateful ones are not.
Daniel M Kane - One of the best experts on this subject based on the ideXlab platform.
-
Mass Surveillance without the state strongly undetectable algorithm substitution attacks
Computer and Communications Security, 2015Co-Authors: Mihir Bellare, Joseph Jaeger, Daniel M KaneAbstract:We present new algorithm-substitution attacks (ASAs) on symmetric encryption that improve over prior ones in two ways. First, while prior attacks only broke a sub-class of randomized schemes having a property called coin injectivity, our attacks break ALL randomized schemes. Second, while prior attacks are stateful, ours are stateless, achieving a notion of strong undetectability that we formalize. Together this shows that ASAs are an even more dangerous and powerful Mass Surveillance method than previously thought. Our work serves to increase awareness about what is possible with ASAs and to spur the search for deterrents and counter-measures.
-
ACM Conference on Computer and Communications Security - Mass-Surveillance without the State: Strongly Undetectable Algorithm-Substitution Attacks
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015Co-Authors: Mihir Bellare, Joseph Jaeger, Daniel M KaneAbstract:We present new algorithm-substitution attacks (ASAs) on symmetric encryption that improve over prior ones in two ways. First, while prior attacks only broke a sub-class of randomized schemes having a property called coin injectivity, our attacks break ALL randomized schemes. Second, while prior attacks are stateful, ours are stateless, achieving a notion of strong undetectability that we formalize. Together this shows that ASAs are an even more dangerous and powerful Mass Surveillance method than previously thought. Our work serves to increase awareness about what is possible with ASAs and to spur the search for deterrents and counter-measures.
Bertram Poettering - One of the best experts on this subject based on the ideXlab platform.
-
IMACC - Subverting Decryption in AEAD
Cryptography and Coding, 2019Co-Authors: Marcel Armour, Bertram PoetteringAbstract:This work introduces a new class of Algorithm Substitution Attack (ASA) on Symmetric Encryption Schemes. ASAs were introduced by Bellare, Paterson and Rogaway in light of revelations concerning Mass Surveillance. An ASA replaces an encryption scheme with a subverted version that aims to reveal information to an adversary engaged in Mass Surveillance, while remaining undetected by users. Previous work posited that a particular class of AEAD scheme (satisfying certain correctness and uniqueness properties) is resilient against subversion. Many if not all real-world constructions – such as GCM, CCM and OCB – are members of this class. Our results stand in opposition to those prior results. We present a potent ASA that generically applies to any AEAD scheme, is undetectable in all previous frameworks and which achieves successful exfiltration of user keys. We give even more efficient non-generic attacks against a selection of AEAD implementations that are most used in practice. In contrast to prior work, our new class of attack targets the decryption algorithm rather than encryption. We argue that this attack represents an attractive opportunity for a Mass Surveillance adversary. Our work serves to refine the ASA model and contributes to a series of papers that raises awareness and understanding about what is possible with ASAs.
-
FSE - A More Cautious Approach to Security Against Mass Surveillance
Fast Software Encryption, 2015Co-Authors: Jean Paul Degabriele, Pooya Farshim, Bertram PoetteringAbstract:At CRYPTO 2014 Bellare, Paterson, and Rogaway (BPR) presented a formal treatment of symmetric encryption in the light of algorithm substitution attacks (ASAs), which may be employed by ‘big brother’ entities for the scope of Mass Surveillance. Roughly speaking, in ASAs big brother may bias ciphertexts to establish a covert channel to leak vital cryptographic information. In this work, we identify a seemingly benign assumption implicit in BPR’s treatment and argue that it artificially (and severely) limits big brother’s capabilities. We then demonstrate the critical role that this assumption plays by showing that even a slight weakening of it renders the security notion completely unsatisfiable by any, possibly deterministic and/or stateful, symmetric encryption scheme. We propose a refined security model to address this shortcoming, and use it to restore the positive result of BPR, but caution that this defense does not stop most other forms of covert-channel attacks.
-
a more cautious approach to security against Mass Surveillance
Fast Software Encryption, 2015Co-Authors: Jean Paul Degabriele, Pooya Farshim, Bertram PoetteringAbstract:At CRYPTO 2014 Bellare, Paterson, and Rogaway (BPR) presented a formal treatment of symmetric encryption in the light of algorithm substitution attacks (ASAs), which may be employed by ‘big brother’ entities for the scope of Mass Surveillance. Roughly speaking, in ASAs big brother may bias ciphertexts to establish a covert channel to leak vital cryptographic information. In this work, we identify a seemingly benign assumption implicit in BPR’s treatment and argue that it artificially (and severely) limits big brother’s capabilities. We then demonstrate the critical role that this assumption plays by showing that even a slight weakening of it renders the security notion completely unsatisfiable by any, possibly deterministic and/or stateful, symmetric encryption scheme. We propose a refined security model to address this shortcoming, and use it to restore the positive result of BPR, but caution that this defense does not stop most other forms of covert-channel attacks.
Phillip Rogaway - One of the best experts on this subject based on the ideXlab platform.
-
The Moral Character of Cryptographic Work
2015Co-Authors: Phillip RogawayAbstract:Cryptography rearranges power: it configures who can do what, from what. This makes cryptography an inherently political tool, and it confers on the field an intrinsically moral dimension. The Snowden revelations motivate a reassessment of the political and moral positioning of cryptography. They lead one to ask if our inability to effectively address Mass Surveillance constitutes a failure of our field. I believe that it does. I call for a community-wide effort to develop more effective means to resist Mass Surveillance. I plead for a reinvention of our disciplinary culture to attend not only to puzzles and math, but, also, to the societal implications of our work.
-
security of symmetric encryption against Mass Surveillance
International Cryptology Conference, 2014Co-Authors: Mihir Bellare, Kenneth G Paterson, Phillip RogawayAbstract:Motivated by revelations concerning population-wide Surveillance of encrypted communications, we formalize and investigate the resistance of symmetric encryption schemes to Mass Surveillance. The focus is on algorithm-substitution attacks (ASAs), where a subverted encryption algorithm replaces the real one. We assume that the goal of “big brother” is undetectable subversion, meaning that ciphertexts produced by the subverted encryption algorithm should reveal plaintexts to big brother yet be indistinguishable to users from those produced by the real encryption scheme. We formalize security notions to capture this goal and then offer both attacks and defenses. In the first category we show that successful (from the point of view of big brother) ASAs may be mounted on a large class of common symmetric encryption schemes. In the second category we show how to design symmetric encryption schemes that avoid such attacks and meet our notion of security. The lesson that emerges is the danger of choice: randomized, stateless schemes are subject to attack while deterministic, stateful ones are not.
-
CRYPTO (1) - Security of Symmetric Encryption against Mass Surveillance
Advances in Cryptology – CRYPTO 2014, 2014Co-Authors: Mihir Bellare, Kenneth G Paterson, Phillip RogawayAbstract:Motivated by revelations concerning population-wide Surveillance of encrypted communications, we formalize and investigate the resistance of symmetric encryption schemes to Mass Surveillance. The focus is on algorithm-substitution attacks (ASAs), where a subverted encryption algorithm replaces the real one. We assume that the goal of “big brother” is undetectable subversion, meaning that ciphertexts produced by the subverted encryption algorithm should reveal plaintexts to big brother yet be indistinguishable to users from those produced by the real encryption scheme. We formalize security notions to capture this goal and then offer both attacks and defenses. In the first category we show that successful (from the point of view of big brother) ASAs may be mounted on a large class of common symmetric encryption schemes. In the second category we show how to design symmetric encryption schemes that avoid such attacks and meet our notion of security. The lesson that emerges is the danger of choice: randomized, stateless schemes are subject to attack while deterministic, stateful ones are not.
Joseph Jaeger - One of the best experts on this subject based on the ideXlab platform.
-
Mass Surveillance without the state strongly undetectable algorithm substitution attacks
Computer and Communications Security, 2015Co-Authors: Mihir Bellare, Joseph Jaeger, Daniel M KaneAbstract:We present new algorithm-substitution attacks (ASAs) on symmetric encryption that improve over prior ones in two ways. First, while prior attacks only broke a sub-class of randomized schemes having a property called coin injectivity, our attacks break ALL randomized schemes. Second, while prior attacks are stateful, ours are stateless, achieving a notion of strong undetectability that we formalize. Together this shows that ASAs are an even more dangerous and powerful Mass Surveillance method than previously thought. Our work serves to increase awareness about what is possible with ASAs and to spur the search for deterrents and counter-measures.
-
ACM Conference on Computer and Communications Security - Mass-Surveillance without the State: Strongly Undetectable Algorithm-Substitution Attacks
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015Co-Authors: Mihir Bellare, Joseph Jaeger, Daniel M KaneAbstract:We present new algorithm-substitution attacks (ASAs) on symmetric encryption that improve over prior ones in two ways. First, while prior attacks only broke a sub-class of randomized schemes having a property called coin injectivity, our attacks break ALL randomized schemes. Second, while prior attacks are stateful, ours are stateless, achieving a notion of strong undetectability that we formalize. Together this shows that ASAs are an even more dangerous and powerful Mass Surveillance method than previously thought. Our work serves to increase awareness about what is possible with ASAs and to spur the search for deterrents and counter-measures.