Cryptanalysis of the ANSI X9.52 CBCM mode

6Citations
Citations of this article
18Readers
Mendeley users who have this article in their library.

Abstract

In this paper we cryptanalyze the CBCM mode of operation, which was almost included in the ANSI X9.52 Triple-DES Modes of Operation standard. The CBCM mode is a Triple-DES CBC variant which was designed against powerful attacks which control intermediate feedback for the benefit of the attacker. For this purpose, it uses intermediate feedbacks that the attacker cannot control, choosing them as a keyed OFB stream, independent of the plaintexts and the ciphertexts. In this paper we find a way to use even this kind of feedback for the benefit of the attacker, and we present an attack which requires a single chosen ciphertext of 265- blocks which needs to be stored and 259 complexity of analysis (CBCM encryptions) to find the key with a high probability. As a consequence of our attack, ANSI decided to remove the CBCM mode from the proposed standard. © 2002 International Association for Cryptologic Research.

Cite

CITATION STYLE

APA

Biham, E., & Knudsen, L. R. (2002). Cryptanalysis of the ANSI X9.52 CBCM mode. Journal of Cryptology, 15(1), 47–59. https://doi.org/10.1007/s00145-001-0016-5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free