A theoretical treatment of related-key attacks: RKA-PRPS, RKA-PRFs, and applications

  • Authors:
  • Mihir Bellare;Tadayoshi Kohno

  • Affiliations:
  • Dept. of Computer Science & Engineering, University of California at San Diego, La Jolla, California;Dept. of Computer Science & Engineering, University of California at San Diego, La Jolla, California

  • Venue:
  • EUROCRYPT'03 Proceedings of the 22nd international conference on Theory and applications of cryptographic techniques
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

We initiate a theoretical investigation of the popular blockcipher design-goal of security against "related-key attacks" (RKAs). We begin by introducing definitions for the concepts of PRPs and PRFs secure against classes of RKAs, each such class being specified by an associated set of "related-key deriving (RKD) functions." Then for some such classes of attacks, we prove impossibility results, showing that no block-cipher can resist these attacks while, for other, related classes of attacks that include popular targets in the block cipher community, we prove possibility results that provide theoretical support for the view that security against them is achievable. Finally we prove security of various block-cipher based constructs that use related keys, including a tweakable block cipher given in [14].