On improved security bounds of one block ciphers mode of operation for protection of block-oriented system storage devices
摘要
In the end of 2022 in Russian Federation recommendations for standardization were adopted defining a block ciphers mode of operation for block-oriented storage devices protection. This mode is called Disk Encryption with Counter (DEC). It has several operational characteristics, that complicate its use for system partition encryption. Therefore, synthesis of alternative modes for full disk encryption (FDE) is in demand. In the most of existing software for system partition encryption XTS mode is used, but it has several properties, that lead to degradation of its cryptographic qualities. This paper describes a provably secure modification of XTS mode—XEH (Xor-Encrypt-Hash) mode defined in our previous works. In this paper, we introduce chosen ciphertext attack (CCA) model for FDE setting and prove security bounds of the XEH mode in this model. Furthermore, performance characteristics of XEH mode were investigated.