Constructing and Deconstructing Intentional Weaknesses in Symmetric Ciphers
Christof Beierle, Tim Beyne, Patrick Felke, Gregor Leander
摘要
Deliberately weakened ciphers are of great interest in political discussion on law enforcement, as in the constantly recurring crypto wars, and have been put in the spotlight of academics by recent progress. A paper at Eurocrypt 2021 showed a strong indication that the security of the widely-deployed stream cipher GEA-1 was deliberately and secretly weakened to 40 bits in order to fulfill European export restrictions that have been in place in the late 1990s. However, no explanation of how this could have been constructed was given. On the other hand, we have seen the MALICIOUS design framework, published at CRYPTO 2020, that allows to construct tweakable block ciphers with a backdoor, where the difficulty of recovering the backdoor relies on well-understood cryptographic assumptions. The constructed tweakable block cipher however is rather unusual and very different from, say, general-purpose ciphers like the AES.
In this paper, we pick up both topics. For GEA-1 we thoroughly explain how the weakness was constructed, solving the main open question of the work mentioned above. By generalizing MALICIOUS we -- for the first time -- construct backdoored tweakable block ciphers that follow modern design principles for general-purpose block ciphers, i.e., more natural-looking deliberately weakened tweakable block ciphers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper3
- The MALICIOUS Framework: Embedding Backdoors into Tweakable Block CiphersThomas Peyrin, Haoyang WangCRYPTO 2020 · 被引用 23 次
- Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent 等EUROCRYPT 2021 · 被引用 22 次
- Refined Cryptanalysis of the GPRS Ciphers GEA-1 and GEA-2Dor Amzaleg, Itai DinurEUROCRYPT 2022 · 被引用 10 次
相关 Paper
- On Perfect Linear Approximations and Differentials over Two-Round SPNsChristof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 等CRYPTO 2023 · 被引用 5 次
- Exploiting Strong Key Bridges: Full-Fledged Automatic Rectangle Attacks on Deoxys-BC and SKINNYLing Song, Yincen Chen, Qianqian Yang, Huimin Liu 等CRYPTO 2026
- Truncated Boomerang Attacks and Application to AES-Based CiphersAugustin Bariant, Gaëtan LeurentEUROCRYPT 2023 · 被引用 29 次
- Tweakable Permutation-Based Luby-Rackoff ConstructionsBishwajit Chakraborty, Abishanka SahaCRYPTO 2025
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 被引用 4 次
