Attacks on the ESA-PSS-04-151 MAC scheme

0Citations
Citations of this article
16Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

The ESA-PSS-04-151 Authentication Layer of the European Space Agency is a MAC mechanism for authenticating telecommands transmitted to spacecrafts. We show that in spite of the very large key length of 2940 bits there are (under certain circumstances) feasible known message attacks. In particular, we show that an attacker who is given about n ≈ 80-100 message/MAC pairs and 60 special bits of the key can forge the MAC of any further message with high probability (> 5% for n = 100) by a single LLL lattice reduction modulo 248 of a matrix of size approximately (n - 60) × n. Most of the 2880 remaining key bits can also be recovered. Furthermore, we show that the attacker can find the 60 special key bits as well if he is given, in addition, another set of about 40-50 message/MAC pairs of a special kind with a workload of less than 231 LLL lattice reductions modulo 248 of the same size. © Springer-Verlag Berlin Heidelberg 2007.

Cite

CITATION STYLE

APA

Illies, G., & Margraf, M. (2007). Attacks on the ESA-PSS-04-151 MAC scheme. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 4876 LNCS, pp. 296–310). Springer Verlag. https://doi.org/10.1007/978-3-540-77360-3_19

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free