On the tightness of CRISP security bounds
摘要
CRISP is a standardized Russian cryptographic protocol for resource-constrained environments. The protocol ensures confidentiality, integrity and protection against replay attacks. A proof of CRISP security in a special formal model was recently presented at CTCrypt 2023. Upper estimates on the distinguishing advantage of the adversary (“real” protocol or “ideal” one) were also obtained there. We now derive a lower bound on insecurity by presenting (low-probability) attacks on the confidentiality and integrity of CRISP. The upper and lower bounds for most cases coincide to within a small constant, so we can conclude that the security bounds of CRISP are tight.