错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Bit-Wise Analysis for Forgery Attacks on AES-Based AEAD Schemes

  • Takuro Shiraya,
  • Kosei Sakamoto,
  • Takanori Isobe

摘要

We examine the security of AES-based authenticated encryption schemes, including the AEGIS family, Tiaoxin-346, Rocca and Rocca-S. Existing studies evaluated the security against forgery attacks, focusing on state collisions in the encryption phase. These studies estimated the lower bounds for the number of active S-boxes by a byte-wise search. However, this approach might underestimate these bounds, as it potentially include invalid characteristics. In this paper, we conduct a bit-wise evaluation of the AEGIS family, Tiaoxin-346, Rocca, and Rocca-S against forgery attacks based on state collision by Boolean satisfiability problem (SAT) tools. This approach enables us to derive tighter bounds for the minimum number of active S-boxes. Besides, for AEGIS-128L, Tiaoxin-346, and Rocca, we incorporate values of differential distribution tables of S-boxes to obtain the exact differential characteristics probability, which directly lead to actual forgery attacks on AEGIS-128L, Tiaoxin-346, and Rocca. These results reveal that AEGIS-128L cannot claim 256-bit security for forgery attacks, even with a 256-bit tag. Furthermore, for the first time, we perform a security evaluation against forgery attacks exploiting tag collisions in the tag generation phase.