AES and Attacks on Cryptographic Hashes.ppt
《AES and Attacks on Cryptographic Hashes.ppt》由会员分享,可在线阅读,更多相关《AES and Attacks on Cryptographic Hashes.ppt(83页珍藏版)》请在麦多课文档分享上搜索。
1、AES and Attacks on Cryptographic HashesJohn MPortions 2004-2005, John Manferdelli. This material is provided without warranty of any kind including, without limitation, warranty of non-infringement or suitability for any purpose. This material is not guaranteed to be error free and is intended for i
2、nstructional use only.JLM 20060212 14:16 1AES History Call for DES successor 1/97 Square begets Rijndael (1998) Rijndael Designers: Vincent Rijmen and Joan Daemen Nine Submissions CAST-256, CRYPTON, DEAL, DFC (cipher), E2, FROG, HPC, LOKI97, MAGENTA, MARS, RC6, Rijndael, SAFER+, Serpent, and Twofish
3、. Finalists MARS, RC6, Rijndael, Serpent, and Twofish FIPS 197 published 11/2001JLM 20060212 14:16 2AESPlaintextCiphertextr Roundsk1k2krKey ScheduleKeyJLM 20060212 14:16 3AES Requirements 128, 192, 256 bit keys Algorithms will be judged on the following factors: Actual security of the algorithm comp
4、ared to other submitted algorithms (at the same key and block size). The extent to which the algorithm output is indistinguishable from a random permutation on the input block. Soundness of the mathematical basis for the algorithms security. Other security factors raised by the public during the eva
5、luation process, including any attacks which demonstrate that the actual security of the algorithm is less than the strength claimed by the submitter. Claimed attacks will be evaluated for practicality. Key agility (NSA): “Two blocks encrypted with two different keys should not take much more time t
6、han two blocks encrypted with the same key.JLM 20060212 14:16 4Mars (Multiplication, Addition, Rotation and Substitution)Basic Structure1. Whiten2. 8 rounds of key independent mixing3. 16 rounds of keyed Feistel transforms (2 S-boxes)4. 8 rounds of key independent mixing5. WhitenJLM 20060212 14:16 5
7、RC6 Design Philosophy Leverage our experience with RC5: use data-dependent rotations to achieve a high level of security. Adapt RC5 to meet AES requirements Take advantage of a new primitive for increased security and efficiency: 32x32 multiplication, which executes quickly on modern processors, to
8、compute rotation amounts.Slide by Ron Rivest (Second AES Conference)JLM 20060212 14:16 6Estimate of number of plaintext pairs required to mount a differential attack. (Only 2128 such pairs are available.)Rounds Pairs8 25612 211716 219020 RC6 223824 2299Security against differential attacksInfeasible
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- AESANDATTACKSONCRYPTOGRAPHICHASHESPPT
