Exploiting AES Encryption Vulnerabilities Through Padding Oracle Attacks and Generative AI Techniques

Priya L, S. Kapilamithran · 2024

In the field of cybersecurity, the need for reliable encryption algorithm is vast. Advanced Encryption Standard (AES) stands as a widely utilized cryptographic algorithm for securing sensitive data. In today’s world, AES is used for performing common packets encryption to bank webpage password encryption. The emergence of complex attacks creates challenges to the safety in using AES. The paper explores the combination of Padding Oracle Attack (POA) techniques and Gen AI methodologies to break AES encryption and predict passwords based on webpage contents. The proposed methodology explores around exploiting vulnerabilities inherent in the padding mechanism of AES. Using padding oracle, the attacker can find the length of the plaintext using the encrypted text. The paper aims to crack the underlying AES key by deducing the length of the encrypted password. Once the length is obtained, decryption and encryption processes are employed iteratively to reveal the AES key, subsequently enabling the extraction of the plaintext passwords. The paper aims to provide real-time evidence of the vulnerability of AES encryption, contributing to the enhancement of encryption standards as part of ethical hacking. The proposed approach is expected to demonstrate the feasibility of predicting passwords based on webpage contents, thereby highlighting the significance of reinforcing encryption protocols and understanding cybersecurity measures against evolving threats.

Read the paper · More papers on PaperTik