[Resource Topic] 2014/901: A Practical Attack Against the Use of RC4 in the HIVE Hidden Volume Encryption System

Welcome to the resource topic for 2014/901

Title:
A Practical Attack Against the Use of RC4 in the HIVE Hidden Volume Encryption System

Authors: Kenneth G. Paterson, Mario Strefler

Abstract:

The HIVE hidden volume encryption system was proposed by Blass et al. at ACM-CCS 2014. Even though HIVE has a security proof, this paper demonstrates an attack on its implementation that breaks the main security property claimed for the system by its authors, namely plausible hiding against arbitrary-access adversaries. Our attack is possible because of the HIVE implementation’s reliance on the RC4 stream cipher to fill unused blocks with pseudorandom data. While the attack can be easily eliminated by using a better pseudorandom generator, it serves as an example of why RC4 should be avoided in all new applications and a reminder that one has to be careful when instantiating primitives.

ePrint: https://eprint.iacr.org/2014/901

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .