Efficient and optimally secure key-length extension for block ciphers via randomized cascading

  • Authors:
  • Peter Gaži;Stefano Tessaro

  • Affiliations:
  • Department of Computer Science, Comenius University, Bratislava, Slovakia and Department of Computer Science, ETH Zurich, Switzerland;Department of Computer Science and Engineering, University of California San Diego, La Jolla, CA, USA and MIT, Cambridge, MA

  • Venue:
  • EUROCRYPT'12 Proceedings of the 31st Annual international conference on Theory and Applications of Cryptographic Techniques
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

We consider the question of efficiently extending the key length of block ciphers. To date, the approach providing highest security is triple encryption (used e.g. in Triple-DES), which was proved to have roughly κ+min {n/2, κ/2} bits of security when instantiated with ideal block ciphers with key length κ and block length n, at the cost of three block-cipher calls per message block. This paper presents a new practical key-length extension scheme exhibiting κ+n/2 bits of security --- hence improving upon the security of triple encryption --- solely at the cost of two block cipher calls and a key of length κ+n. We also provide matching generic attacks showing the optimality of the security level achieved by our approach with respect to a general class of two-query constructions.