On the perfect encryption assumption

Olivier Pereira, Jean-Jacques Quisquater · 2000

Nearly all models proposed within the scope of the study of security protocols make perfect encryption assumptions. These hypotheses can be summarised as follow:- The decryption key must be known in order to extract the plaintext corresponding to a given ciphertext.- There is enough redundancy in the cryptosystem that a ciphertext can only be generated using encryption with the appropriate key and message. This assumption is obviously not true in practice. A first example is the one of the cryptosystems proceeding by cipher-block-chaining (CBC). In such systems, the encryption of message block sequence P1P2…Pn is C0C1C2…Cn where C0=I (Initialisation bloc) and Ci={Ci-1⊕Pi}K. It can be noticed that they present the following interesting particularity: If C0C1C2…CiCi+1…Cn = {P1P2…PiPi+1…Pn}K Then C0C1C2…Ci = {P1P2…Pi}K This property can be exploited (see [Boy90] or [SG92] for other instances) to flaw the Needham-Schroeder symmetric key authentication protocol [NS78]. This protocol intends to permit Alice to establish a shared secret key Kab with Bob and to obtain mutual conviction of the possession of the key by each other. The key is provided by a trusted server S who shares the secret keys Kas and Kbs with A and B respectively. This protocol can be described as follow:

Read the paper · More papers on PaperTik