[Resource Topic] 2013/357: The LOCAL attack: Cryptanalysis of the authenticated encryption scheme ALE

Welcome to the resource topic for 2013/357

Title:
The LOCAL attack: Cryptanalysis of the authenticated encryption scheme ALE

Authors: Dmitry Khovratovich, Christian Rechberger

Abstract:

We show how to produce a forged (ciphertext,tag) pair for the scheme ALE with data and time complexity of 2^102 ALE encryptions of short messages and the same number of authentication attempts. We use a differential attack based on a local collision, which exploits the availability of extracted state bytes to the adversary. Our approach allows for a time-data complexity tradeoff, with an extreme case of a forgery produced after $2^119 attempts and based on a single authenticated message. Our attack is further turned into a state recovery and a universal forgery attack with a time complexity of 2^120 verification attempts using only a single authenticated 48-byte message.

ePrint: https://eprint.iacr.org/2013/357

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .