A Chosen Key Difference Attack on Control Vectors
Mike Bond · 2000
An attack on the implementation of control vectors in the IBM Common Cryptographic Architecture is presented. The final key−part holder in a multiple part import introduces two key−encrypting keys (KEKs), one the intended key and one with a chosen difference from the former, by including this difference in his own key part. When this difference is set to the difference between two control vectors, keys originally encrypted with the former KEK can be cast to a new type by importing them under the latter KEK. Thus unauthorised type−casts can be made from an arbitrary source type to any destination type the attacker has permission to use. 1