The Experts below are selected from a list of 216 Experts worldwide ranked by ideXlab platform
Lars Ramkilde Knudsen - One of the best experts on this subject based on the ideXlab platform.
-
Provable security against a differential attack
Journal of Cryptology, 1995Co-Authors: Kaisa Nyberg, Lars Ramkilde KnudsenAbstract:The purpose of this paper is to show that DES-like iterated ciphers that are provably resistant against differential attacks exist. The main result on the security of a DES-like cipher with independent round keys is Theorem 1, which gives an upper bound to the probability of s -round differentials, as defined in [4], and this upper bound depends only on the round function of the iterated cipher. Moreover, it is shown that functions exist such that the probabilities of differentials are less than or equal to 2^3− n , where n is the length of the Plaintext Block. We also show a prototype of an iterated Block cipher, which is compatible with DES and has proven security against differential attack.
-
Provable Security Against a Differential Attack
DAIMI Report Series, 1994Co-Authors: Kaisa Nyberg, Lars Ramkilde KnudsenAbstract:The purpose of this paper is to show that there exist DES-like iterated ciphers, which are provably resistant against differential attacks. The main result on the security of a DES-like cipher with independent round keys is Theorem 1, which gives an upper bound to the probability of s -round differentials, as defined in Markov Ciphers and Differential Cryptanalysis by X. Lai et al. and this upper bound depends only on the round function of the iterated cipher. Moreover, it is shown that there exist functions such that the probabilities of differentials are less than or equal to 2 3-n , where n is the length of the Plaintext Block. We also show a prototype of an iterated Block cipher, which is compatible with DES and has proven security against differential attacks.
-
CRYPTO - Provable Security Against Differential Cryptanalysis
Advances in Cryptology — CRYPTO’ 92, 1Co-Authors: Kaisa Nyberg, Lars Ramkilde KnudsenAbstract:The purpose of this paper is to show that there exist DES-like iterated ciphers, which are provably resistant against differential attacks. The main result on the security of a DES-like cipher with independent round keys is Theorem 1, which gives an upper bound to the probability of r-round differentials, as defined in [3] and this upper bound depends only on the round function of the iterated cipher. Moreover, it is shown that there exist functions such that the probabilities of differentials are less than or equal to 22 − n where n is the length of the Plaintext Block. We also show a prototype of an iterated Block cipher, which is compatible with DES and has proven security against differential attacks.
Kaisa Nyberg - One of the best experts on this subject based on the ideXlab platform.
-
Provable security against a differential attack
Journal of Cryptology, 1995Co-Authors: Kaisa Nyberg, Lars Ramkilde KnudsenAbstract:The purpose of this paper is to show that DES-like iterated ciphers that are provably resistant against differential attacks exist. The main result on the security of a DES-like cipher with independent round keys is Theorem 1, which gives an upper bound to the probability of s -round differentials, as defined in [4], and this upper bound depends only on the round function of the iterated cipher. Moreover, it is shown that functions exist such that the probabilities of differentials are less than or equal to 2^3− n , where n is the length of the Plaintext Block. We also show a prototype of an iterated Block cipher, which is compatible with DES and has proven security against differential attack.
-
Provable Security Against a Differential Attack
DAIMI Report Series, 1994Co-Authors: Kaisa Nyberg, Lars Ramkilde KnudsenAbstract:The purpose of this paper is to show that there exist DES-like iterated ciphers, which are provably resistant against differential attacks. The main result on the security of a DES-like cipher with independent round keys is Theorem 1, which gives an upper bound to the probability of s -round differentials, as defined in Markov Ciphers and Differential Cryptanalysis by X. Lai et al. and this upper bound depends only on the round function of the iterated cipher. Moreover, it is shown that there exist functions such that the probabilities of differentials are less than or equal to 2 3-n , where n is the length of the Plaintext Block. We also show a prototype of an iterated Block cipher, which is compatible with DES and has proven security against differential attacks.
-
CRYPTO - Provable Security Against Differential Cryptanalysis
Advances in Cryptology — CRYPTO’ 92, 1Co-Authors: Kaisa Nyberg, Lars Ramkilde KnudsenAbstract:The purpose of this paper is to show that there exist DES-like iterated ciphers, which are provably resistant against differential attacks. The main result on the security of a DES-like cipher with independent round keys is Theorem 1, which gives an upper bound to the probability of r-round differentials, as defined in [3] and this upper bound depends only on the round function of the iterated cipher. Moreover, it is shown that there exist functions such that the probabilities of differentials are less than or equal to 22 − n where n is the length of the Plaintext Block. We also show a prototype of an iterated Block cipher, which is compatible with DES and has proven security against differential attacks.
Fatma Ahmed - One of the best experts on this subject based on the ideXlab platform.
-
New Cryptosystem Based on IDEA with Optimal Diffusion 8x8 MDS Matrix
2013Co-Authors: M. R. M. Rizk, Fatma AhmedAbstract:The increasing ubiquity of information technologies in all aspects of human life makes security issues one of the most critical aspects of system design. In this paper we introduce a new symmetric cryptosystem based on IDEA system. The Plaintext Block is divided into basic sub-Blocks each of thirty-two bits in length. The new Proposal can encrypt Blocks of Plaintext of length 512 bits into Blocks of the same length. The key length is 1024 bits. The total number of rounds is 16. It uses modulo 32 2
-
A NEW GAUSSIAN CIPHER WITH OPTIMAL KEYED PROCESS (KAM-FA)
2013Co-Authors: Hassan M. Elkamchouchi, Fatma AhmedAbstract:Nowadays, cryptography plays a major role in protecting the information of technology applications. This paper gives a new symmetric cryptosystem having a key dependent operation, enhanced by a rotor with controlled user identification ID and user key. The Plaintext Block is divided into basic Gaussian subBlocks each of thirty-two bits in length. The new Proposal uses optimal MDS matrix. The new Proposal can encrypt Blocks of Plaintext of length 512 bits into Blocks of the same length. Also the key length is 512 bits. The total number of rounds is sixteen rounds. It uses
-
ENHANCED IDEA ALGORITHM FOR STRONG ENCRYPTION BASED ON EFFICIENT STRONG ROTOR BANKS
2013Co-Authors: Hassan M. Elkamchouchi, Fatma AhmedAbstract:Information security becomes an important issue of the communication networks. In this paper we propose a new symmetric cryptosystem based on IDEA system. The Plaintext Block is divided into basic sub-Blocks each of thirty-two bits in length. The new Proposal can encrypt Blocks of Plaintext of length 512 bits into Blocks of the same length. The key length is 1024 bits. The total number of rounds is 17. It uses modulo 32 2 multiplication which is prime number to increase the field in multiplication operation. It uses a new efficient and strong rotor bank which provides best resistance against linear and differential cryptanalysis, also provides better resistance against algebraic attack because it is implemented using Kasami Exponent function one of APN (Almost Perfect Nonlinear) function. The rotor banks rotate by irregular step and we use it to generate the subkeys which give us high diffusion and confusion. In this system, we try to get the minimum correlation between Plaintext and ciphertext, highly avalanche effect and defeat the frequency analysis and most well-known attacks. The new algorithm is compared with IDEA and gives excellent results from the viewpoint of the security characteristics and the statistics of the ciphertext. Also, we apply the randomness test to the proposed algorithm and the results shown that the new design passes all tests which proven its security.
-
rotor cipher with time controlled key and encryption process rtckp
National Radio Science Conference, 2009Co-Authors: Hassan M Elkamachouchi, Fatma AhmedAbstract:This paper gives a new symmetric cryptosystem having a key dependent Block length and key dependent rounds, enhanced by a rotor with controlled time and key. The Plaintext Block is divided into basic sub-Blocks each of thirty-two bits in length. The new Proposal can encrypt Blocks of Plaintext of length 256, 512, or 1024 bits into Blocks of the same length. Also the key length can be 256, 512, or 1024 bits. The total number of rounds depends on the key length. It uses thirty-two bits S-boxes implemented using thirty-two bits affine transformation modulo 232 addition and thirty-two bits XORING are used followed by modulo 232 + 1 multiplication. The secret key is encrypted using a key rotor to avoid any weakness points in the user keys. The proposal performs a complex set of operations on the encrypted secret key to produce a set subkeys. Also it uses three banks of rotors. The first bank performs the encryption process. It uses sixteen cylinders operating on all the 256 ASCII characters arranged using a local time array. The second bank has four cylinders that are used in three operations. The first operation is to encrypt the user key. In this step, the rotor is arranged by the local time array of length t. The second operation is to encrypt the local time array. In this step, the user key arranges the rotor. The third operation is used to encrypt each letter of Plaintext. The resulting output is then used in index bank to determine which cylinder in the first bank will turn after this letter is encrypted. The proposed algorithm is compared with the well known DES, AES and REBC symmetric systems and gives excellent results from the point of view of the security characteristics and the statistics of the ciphertext.
T N Vijaykumar - One of the best experts on this subject based on the ideXlab platform.
-
accelerating private key cryptography via multithreading on symmetric multiprocessors
International Symposium on Performance Analysis of Systems and Software, 2003Co-Authors: Praveen K Dongara, T N VijaykumarAbstract:Achieving high performance in cryptographic processing is important due to the increasing connectivity among today's computers. Despite steady improvements in microprocessor and system performance, private-key cipher implementations continue to be slow. Irrespective of the cipher used, the main reason for the low performance is lack of parallelism, which fundamentally comes from encryption modes such as the Cipher Block Chaining (CBC) mode. In CBC, each Plaintext Block is XOR'ed with the previous ciphertext Block and then encrypted, essentially inducing a tight recurrence through the ciphertext Blocks. To deliver high performance while maintaining high level of security assurance in real systems, the cryptography community has proposed Interleaved Cipher Block Chaining (ICBC) mode. In four-way interleaved chaining, the first, fifth, and every fourth Block thereafter are encrypted in CBC mode; the second, sixth, and every fourth Block thereafter are encrypted as another stream, and so on. Thus, interleaved chaining loosens the recurrence imposed by CBC, enabling the multiple encryption streams to be overlapped. The number of interleaved chains can be chosen to balance performance and adequate chaining to get good data diffusion. While ICBC was originally proposed to improve hardware encryption rates by employing multiple encryption chips in parallel, this is the first paper to evaluate ICBC via multithreading commonly-used ciphers on a symmetric multiprocessor (SMP). ICBC allows exploiting the full processing power of SMPs, which spend many cycles in cryptographic processing as medium-scale servers today, and will do so as chip-multiprocessor clients in the future. Using the Wisconsin Wind Tunnel II, we show that our multithreaded ciphers achieve encryption rates of 92 Mbytes/s on a 16-processor SMP at 1 GHz, reaching a factor of almost 10 improvement oiler a uniprocessor, which achieves 9 Mbytes/s.
-
ISPASS - Accelerating private-key cryptography via multithreading on symmetric multiprocessors
2003 IEEE International Symposium on Performance Analysis of Systems and Software. ISPASS 2003., 1Co-Authors: Praveen K Dongara, T N VijaykumarAbstract:Achieving high performance in cryptographic processing is important due to the increasing connectivity among today's computers. Despite steady improvements in microprocessor and system performance, private-key cipher implementations continue to be slow. Irrespective of the cipher used, the main reason for the low performance is lack of parallelism, which fundamentally comes from encryption modes such as the Cipher Block Chaining (CBC) mode. In CBC, each Plaintext Block is XOR'ed with the previous ciphertext Block and then encrypted, essentially inducing a tight recurrence through the ciphertext Blocks. To deliver high performance while maintaining high level of security assurance in real systems, the cryptography community has proposed Interleaved Cipher Block Chaining (ICBC) mode. In four-way interleaved chaining, the first, fifth, and every fourth Block thereafter are encrypted in CBC mode; the second, sixth, and every fourth Block thereafter are encrypted as another stream, and so on. Thus, interleaved chaining loosens the recurrence imposed by CBC, enabling the multiple encryption streams to be overlapped. The number of interleaved chains can be chosen to balance performance and adequate chaining to get good data diffusion. While ICBC was originally proposed to improve hardware encryption rates by employing multiple encryption chips in parallel, this is the first paper to evaluate ICBC via multithreading commonly-used ciphers on a symmetric multiprocessor (SMP). ICBC allows exploiting the full processing power of SMPs, which spend many cycles in cryptographic processing as medium-scale servers today, and will do so as chip-multiprocessor clients in the future. Using the Wisconsin Wind Tunnel II, we show that our multithreaded ciphers achieve encryption rates of 92 Mbytes/s on a 16-processor SMP at 1 GHz, reaching a factor of almost 10 improvement oiler a uniprocessor, which achieves 9 Mbytes/s.
Elena Andreeva - One of the best experts on this subject based on the ideXlab platform.
-
Turning Online Ciphers Off
IACR Cryptology ePrint Archive, 2017Co-Authors: Elena Andreeva, Guy Barwell, Ritam Bhaumik, Mridul Nandi, Daniel Page, Martijn StamAbstract:CAESAR has caused a heated discussion regarding the merits of one-pass encryption and online ciphers. The latter is a keyed, length preserving function which outputs ciphertext Blocks as soon as the respective Plaintext Block is available as input. The immediacy of an online cipher affords a clear performance advantage, but it comes at a price: ciphertext Blocks cannot depend on later Plaintext Blocks, limiting diffusion and hence security. We show how one can attain the best of both worlds by providing provably secure constructions, achieving full cipher security, based on applications of an online cipher around Blockwise reordering layers. Explicitly, we show that with just two calls to the online cipher, prp security up to the birthday bound is both attainable and maximal. Moreover, we demonstrate that three calls to the online cipher suffice to obtain beyond birthday bound security. We provide a full proof of this for a prp construction, and, in the ±prp setting, security against adversaries who make queries of any single length. As part of our investigation, we extend an observation by Rogaway and Zhang by further highlighting the close relationship between online ciphers and tweakable Blockciphers with variable-length tweaks.
-
ASIACRYPT (1) - Parallelizable and Authenticated Online Ciphers
Advances in Cryptology - ASIACRYPT 2013, 2013Co-Authors: Elena Andreeva, Andrey Bogdanov, Atul Luykx, Bart Mennink, Elmar Tischhauser, Kan YasudaAbstract:Online ciphers encrypt an arbitrary number of Plaintext Blocks and output ciphertext Blocks which only depend on the preceding Plaintext Blocks. All online ciphers proposed so far are essentially serial, which significantly limits their performance on parallel architectures such as modern general-purpose CPUs or dedicated hardware.We propose the first parallelizable online cipher, COPE. It performs two calls to the underlying Block cipher per Plaintext Block and is fully parallelizable in both encryption and decryption. COPE is proven secure against chosenPlaintext attacks assuming the underlying Block cipher is a strong PRP. We then extend COPE to create COPA, the first parallelizable, online authenticated cipher with nonce-misuse resistance. COPA only requires two extra Block cipher calls to provide integrity. The privacy and integrity of the scheme is proven secure assuming the underlying Block cipher is a strong PRP. Our implementation with Intel AES-NI on a Sandy Bridge CPU architecture shows that both COPE and COPA are about 5 times faster than their closest competition: TC1, TC3, and McOE-G. This high factor of advantage emphasizes the paramount role of parallelizability on up-to-date computing platforms.
-
Parallelizable and Authenticated Online Ciphers.
IACR Cryptology ePrint Archive, 2013Co-Authors: Elena Andreeva, Andrey Bogdanov, Atul Luykx, Bart Mennink, Elmar Tischhauser, Kan YasudaAbstract:Online ciphers encrypt an arbitrary number of Plaintext Blocks and output ciphertext Blocks which only depend on the preceding Plaintext Blocks. All online ciphers proposed so far are essentially serial, which significantly limits their performance on parallel architectures such as modern general-purpose CPUs or dedicated hardware. We propose the first parallelizable online cipher, COPE. It performs two calls to the underlying Block cipher per Plaintext Block and is fully parallelizable in both encryption and decryption. COPE is proven secure against chosen-Plaintext attacks assuming the underlying Block cipher is a strong PRP. We then extend COPE to create COPA, the first parallelizable, online authenticated cipher with nonce-misuse resistance. COPA only requires two extra Block cipher calls to provide integrity. The privacy and integrity of the scheme is proven secure assuming the underlying Block cipher is a strong PRP. Our implementation with Intel AES-NI on a Sandy Bridge CPU architecture shows that both COPE and COPA are about 5 times faster than their closest competition: TC1, TC3, and McOE-G. This high factor of advantage emphasizes the paramount role of parallelizability on up-to-date computing platforms.