Lune

EUROCRYPT2021顶会

Three Third Generation Attacks on the Format Preserving Encryption Scheme FF3

Ohad Amon, Orr Dunkelman, Nathan Keller, Eyal Ronen, Adi Shamir

2021年份
8被引次数

摘要

Format-Preserving Encryption (FPE) schemes accept plaintexts from any finite set of values (such as social security numbers or birth dates) and produce ciphertexts that belong to the same set. They are extremely useful in practice since they make it possible to encrypt existing databases or communication packets without changing their format. Due to industry demand, NIST had standardized in 2016 two such encryption schemes called FF1 and FF3. They immediately attracted considerable cryptanalytic attention with decreasing attack complexities. The best currently known attack on the Feistel construction FF3 has data and memory complexity of O(N11/6){O}(N^{11/6}) and time complexity of O(N17/6){O}(N^{17/6}), where the input belongs to a domain of size N×NN \times N.

In this paper, we present and experimentally verify three improved attacks on FF3. Our best attack achieves the tradeoff curve D=M=O~(N2−t)D=M=\tilde{O}(N^{2-t}), T=O~(N2+t)T=\tilde{O}(N^{2+t}) for all t≤0.5t \leq 0.5. In particular, we can reduce the data and memory complexities to the more practical O~(N1.5)\tilde{O}(N^{1.5}), and at the same time, reduce the time complexity to O~(N2.5)\tilde{O}(N^{2.5}).

We also identify another attack vector against FPE schemes, the related-domain attack. We show how one can mount powerful attacks when the adversary is given access to the encryption under the same key in different domains, and show how to apply it to efficiently distinguish FF3 and FF3-1 instances.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get ceb71e6b-b3f6-4e22-945c-b64c6d1ca06a

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖