首页> 外文期刊>Designs, Codes and Crytography >Separating invertible key derivations from non-invertible ones: sequential indifferentiability of 3-round Even-Mansour
【24h】

Separating invertible key derivations from non-invertible ones: sequential indifferentiability of 3-round Even-Mansour

机译:将不可逆密钥派生与不可逆密钥派生区分开来:3轮Even-Mansour的顺序不可微性

获取原文
获取原文并翻译 | 示例
           

摘要

Iterated Even-Mansour (IEM) scheme consists of a small number r of fixed n-bit permutations separated by round-key additions. When the permutations are public, independent and random, and a common round key derived from the master key by an idealized non-invertible key derivation (KD) function is used, 5 rounds was proved sufficient to obtain (full) indifferentiability from ideal ciphers by Andreeva et al. (CRYPTO 2013). The KD can be a random oracle, or a Davies-Meyer construction from a random permutation. This work considers such IEM with non-invertible KD in the sequential indifferentiability model of Mandal et al. (TCC 2012). As results, this work shows that in both cases mentioned before, 3 rounds yields sequential indifferentiability from ideal ciphers. As Andreeva et al. has proved 3-round IEM with idealized invertible key derivations not sequentially indifferentiable (by exhibiting an attack), a definitive separation between IEM with invertible key derivations and IEM with non-invertible key derivations is established. This is the most important implication of the results in this work.
机译:迭代偶数Mansour(IEM)方案由少量r个固定n位置换组成,这些置换通过圆键加法分隔。当排列是公共的,独立的和随机的,并且使用通过理想化的不可逆密钥推导(KD)函数从主密钥派生的公共轮密钥时,经证明5个轮足以从理想密码获得(完全)不可分性。 Andreeva等。 (CRYPTO 2013)。 KD可以是随机预言,也可以是随机排列的Davies-Meyer构造。这项工作在Mandal等人的顺序不可微模型中考虑了具有不可逆KD的IEM。 (TCC 2012)。结果,这项工作表明,在前面提到的两种情况下,三轮都与理想密码产生连续的不可区分性。如Andreeva等。已经证明具有理想的可逆密钥派生的3轮IEM不会依序不可区分(通过攻击),因此在具有可逆密钥派生的IEM和具有不可逆密钥派生的IEM之间建立了确定的分隔。这是这项工作中结果最重要的含义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号