Plaintext Recovery and Tag Guessing Attacks on Authenticated Encryption Algorithm Colm

dc.contributor.author Ulusoy, Sırrı Erdem
dc.contributor.author Kara, Orhun
dc.contributor.author Efe, Mehmet Önder
dc.date.accessioned 2022-11-03T11:03:44Z
dc.date.available 2022-11-03T11:03:44Z
dc.date.issued 2022
dc.description.abstract There are three main approaches related to cryptanalysis of Authenticated Encryption with Associated Data (AEAD) algorithms: Simulating the encryption oracle (universal forgery attack), simulating the decryption oracle (plaintext recovery attack) and producing the valid tag of a given ciphertext (tag guessing attack). In this work, we analyze the security of COLM in these approaches. COLM is one of the AEAD algorithms chosen in the final portfolio for defense-in-depth use case of the CAESAR competition. The ciphers in this portfolio are supposed to provide robust security with their multiple layered defense mechanisms. The main motivation of this work is to examine if COLM indeed satisfies defense-in-depth security. We make cryptanalysis of COLM, particularly in the chosen ciphertext attack (CCA) scenario, once its secret whitening parameter L=EK(0) is recovered. To the best of our knowledge, we give the first example of querying an EME/EMD (Encrypt-linearMix-Encrypt/Decrypt) AEAD scheme in its decryption direction for arbitrary ciphertexts, not produced previously by the oracle, namely either a forgery or tag guessing attack. We construct SEBC/SDBC (Simulation models of the Encryption/Decryption oracles of the underlying Block Cipher) of COLM, thereby forming the first examples of these models of an authenticated EME scheme simultaneously. The combination of our SEBC/SDBC is a powerful tool to mount a universal forgery attack, a tag guessing attack and a plaintext recovery attack. All of these attacks have polynomial time complexities once L is recovered in the offline phase, indicating that the security of COLM against plaintext recovery and tag guessing attacks is limited by the birthday bound. Apart from exploiting SEBC/SDBC, we mount a pair of plaintext recovery attacks and another universal forgery attack. Finally, we make some suggestions to prevent our attacks. en_US
dc.identifier.doi 10.1016/j.jisa.2022.103342
dc.identifier.issn 2214-2134 en_US
dc.identifier.issn 2214-2134
dc.identifier.issn 2214-2126
dc.identifier.scopus 2-s2.0-85139999636
dc.identifier.uri https://doi.org/10.1016/j.jisa.2022.103342
dc.identifier.uri https://hdl.handle.net/11147/12589
dc.language.iso en en_US
dc.publisher Elsevier en_US
dc.relation.ispartof Journal of Information Security and Applications en_US
dc.rights info:eu-repo/semantics/embargoedAccess en_US
dc.subject Plaintext recovery en_US
dc.subject AEAD en_US
dc.subject Tag guessing en_US
dc.subject COLM en_US
dc.subject Universal forgery en_US
dc.subject Impossible differential en_US
dc.title Plaintext Recovery and Tag Guessing Attacks on Authenticated Encryption Algorithm Colm en_US
dc.type Article en_US
dspace.entity.type Publication
gdc.author.id 0000-0002-9685-6625
gdc.author.id 0000-0002-9685-6625 en_US
gdc.author.institutional Kara, Orhun
gdc.bip.impulseclass C5
gdc.bip.influenceclass C5
gdc.bip.popularityclass C5
gdc.coar.access embargoed access
gdc.coar.type text::journal::journal article
gdc.collaboration.industrial false
gdc.description.department İzmir Institute of Technology. Mathematics en_US
gdc.description.publicationcategory Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı en_US
gdc.description.scopusquality Q1
gdc.description.volume 70 en_US
gdc.description.wosquality Q2
gdc.identifier.openalex W4304820716
gdc.identifier.wos WOS:000871857600001
gdc.index.type WoS
gdc.index.type Scopus
gdc.oaire.diamondjournal false
gdc.oaire.impulse 0.0
gdc.oaire.influence 2.635068E-9
gdc.oaire.isgreen true
gdc.oaire.popularity 2.2369273E-9
gdc.oaire.publicfunded false
gdc.oaire.sciencefields 0202 electrical engineering, electronic engineering, information engineering
gdc.oaire.sciencefields 02 engineering and technology
gdc.openalex.collaboration National
gdc.openalex.fwci 0.19579882
gdc.openalex.normalizedpercentile 0.54
gdc.opencitations.count 0
gdc.plumx.mendeley 5
gdc.plumx.scopuscites 1
gdc.scopus.citedcount 1
gdc.wos.citedcount 1
relation.isAuthorOfPublication.latestForDiscovery fac6ed1c-26cb-41d9-ba18-b8f37fb59f35
relation.isOrgUnitOfPublication.latestForDiscovery 9af2b05f-28ac-4012-8abe-a4dfe192da5e

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Name:
1-s2.0-S2214212622001879-main.pdf
Size:
1.16 MB
Format:
Adobe Portable Document Format
Description:
Article (Makale)

License bundle

Now showing 1 - 1 of 1
Loading...
Name:
license.txt
Size:
3.2 KB
Format:
Item-specific license agreed upon to submission
Description: