The security of multiple encryption in the ideal cipher model

19Citations
Citations of this article
35Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Multiple encryption - the practice of composing a blockcipher several times with itself under independent keys - has received considerable attention of late from the standpoint of provable security. Despite these efforts proving definitive security bounds (i.e., with matching attacks) has remained elusive even for the special case of triple encryption. In this paper we close the gap by improving both the best known attacks and best known provable security, so that both bounds match. Our results apply for arbitrary number of rounds and show that the security of ℓ-round multiple encryption is precisely exp(k+min{k(ℓ′-2)/2), n(ℓ′-2)/ℓ′}) where exp(t) = 2t and where ell;′ = 2⌈ell;/2⌉ is the smallest even integer greater than or equal to ℓ, for all ℓ ≥ 1. Our technique is based on Patarin's H-coefficient method and relies on a combinatorial result of Chen and Steinberger originally required in the context of key-alternating ciphers. © 2014 International Association for Cryptologic Research.

Cite

CITATION STYLE

APA

Dai, Y., Lee, J., Mennink, B., & Steinberger, J. (2014). The security of multiple encryption in the ideal cipher model. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8616 LNCS, pp. 20–38). Springer Verlag. https://doi.org/10.1007/978-3-662-44371-2_2

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free