Re: ECB+CTR Mode?

From: Tom St Denis (tomstdenis_at_iahu.ca)
Date: 08/11/03


Date: Mon, 11 Aug 2003 14:08:23 GMT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

John E. Hadstate wrote:
| "Mark Wooding" <mdw@nsict.org> wrote in message
| news:slrnbjf0ad.u6.mdw@tux.nsict.org...
|
|>John E. Hadstate <nospam@null.nil> wrote:
|>
|>
|>>CTR mode has the same shortcoming as all stream ciphers: the CT stream
|>>must be authenticated. This causes an expansion of the ciphertext.
|>
|>Ummm... your mode needs authenticating if it's going to resist chosen-
|>ciphertext attacks. But in fact it doesn't even resist chosen-
|>plaintext: it leaks descending sequences.
|>
|
|
| Actually, it leaks other sequences too. See Paul Rubin's response.
|
| I may have hit on a variation that allows authentication and
| integrity-checking without expanding the CT. The assumption would be that
| the application processing the decrypted PT contains some "sanity
checking"
| to ensure that decrypted "garbage" is caught.

"sanity checking" is exactly what a MAC provides.

Tom
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE/N6NUsP+tEsHHY0ARAs8yAJ97GLZ4klIYBjWEESBKVEMyhceNoQCfVMEs
fLh0h7ZNoXaiM12rO6daPW8=
=XUFG
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: ECB+CTR Mode?
    ... John E. Hadstate wrote: ... | "Tom St Denis" wrote in message ... |>John E. Hadstate wrote: ... |>~>>When I asked for clarification you replied with this junk. ...
    (sci.crypt)
  • Re: ECB+CTR Mode?
    ... John E. Hadstate wrote: ... |>John E. Hadstate wrote: ... Consider a problematic plaintext in which the ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
    (sci.crypt)
  • Re: Public disclosure of discovered vulnerabilities
    ... David Wagner wrote: ... >John E. Hadstate wrote: ... >I confess I'm pretty surprised to see you write that. ...
    (sci.crypt)
  • Re: [Lit.] Buffer overruns
    ... John E. Hadstate wrote: ... >If you don't set such high standards for yourself, ... >better for both you and profession if you would find another avocation. ...
    (sci.crypt)
  • Re: Database encryption.
    ... > John E. Hadstate wrote: ... >> based on the original plaintext, but my reading lead me to think that ... >> okay with Indexes based on ciphertext. ... > database fields. ...
    (sci.crypt)

Quantcast