Кіріспе
Блокты шифрлау Blowfish – 1993 жылы Брюс Шнайер жасаған және көптеген шифрлау жиынтықтары мен шифрлау өнімдеріне енгізілген симметриялық кілт блокты шифрлау. Blowfish бағдарламалық жасақтамада жақсы шифрлау жылдамдығын қамтамасыз етеді және оның тиімді криптоанализі әлі күнге дейін табылған жоқ. Алайда, Advanced Encryption Standard (AES) қазір көбірек назар аударады және Шнайер Twofish-ті заманауи қолданбалар үшін ұсынады. Бұл 16 раундты Фейстель шифры және үлкен кілттерге тәуелді S қораптарын пайдаланады. Құрылымы бойынша ол CAST 128 сияқты, ол тұрақты S қораптарын пайдаланады. Жақын диаграммада Blowfish шифрлау реті көрсетілген. Әрбір жол 32 битті білдіреді. Бес кіші кілт массиві бар: бір 18 жазуы бар P массиві (диаграммада K ретінде белгіленеді, ашық мәтінмен шатастырудан сақтану үшін) және төрт 256 жазуы бар S қораптары (S0, S1, S2 және S3). Әр r айналым 4 әрекеттен тұрады:
1. XOR әрекеті: деректердің сол жартысын (L) r-шы P массивінің жазуымен XOR-лау.
2. XOR-далған деректерді Blowfish F функциясының кірісі ретінде пайдалану.
3. F функциясының шығысын деректердің оң жартысымен (R) XOR-лау.
4. L мен R-ді алмастыру.
Blowfish is a symmetric key block cipher, designed in 1993 by Bruce Schneier and included in many cipher suites and encryption products. Blowfish provides a good encryption rate in software, and no effective cryptanalysis of it has been found to date. However, the Advanced Encryption Standard (AES) now receives more attention, and Schneier recommends Twofish for modern applications. It is a 16 round Feistel cipher and uses large key dependent S boxes. In structure it resembles CAST 128, which uses fixed S boxes. The adjacent diagram shows Blowfish's encryption routine. Each line represents 32 bits. There are five subkey arrays: one 18 entry P array (denoted as K in the diagram, to avoid confusion with the Plaintext) and four 256 entry S boxes (S0, S1, S2 and S3). Every round r consists of 4 actions:
Action 1XOR the left half (L) of the data with the r th P array entryAction 2Use the XORed data as input for Blowfish's F functionAction 3XOR the F function's output with the right half (R) of the dataAction 4Swap L and R
The F function splits the 32 bit input into four 8 bit quarters and uses the quarters as input to the S boxes. The S boxes accept 8 bit input and produce 32 bit output. The outputs are added modulo 232 and XORed to produce the final 32 bit output (see image in the upper right corner). After the 16th round, undo the last swap, and XOR L with K18 and R with K17 (output whitening). Decryption is exactly the same as encryption, except that P1, P2, , P18 are used in the reverse order. This is not so obvious because xor is commutative and associative. A common misconception is to use inverse order of encryption as decryption algorithm (i. e. first XORing P17 and P18 to the ciphertext block, then using the P entries in reverse order). Blowfish's key schedule starts by initializing the P array and S boxes with values derived from the hexadecimal digits of pi, which contain no obvious pattern (see nothing up my sleeve number). The secret key is then, byte by byte, cycling the key if necessary, XORed with all the P entries in order. A 64 bit all zero block is then encrypted with the algorithm as it stands. The resultant ciphertext replaces P1 and P2. The same ciphertext is then encrypted again with the new subkeys, and the new ciphertext replaces P3 and P4. This continues, replacing the entire P array and all the S box entries. In all, the Blowfish encryption algorithm will run 521 times to generate all the subkeys about 4 KB of data is processed. Because the P array is 576 bits long, and the key bytes are XORed through all these 576 bits during the initialization, many implementations support key sizes up to 576 bits. The reason for that is a discrepancy between the original Blowfish description, which uses 448 bit keys, and its reference implementation, which uses 576 bit keys. The test vectors for verifying third party implementations were also produced with 576 bit keys. When asked which Blowfish version is the correct one, Bruce Schneier answered: "The test vectors should be used to determine the one true Blowfish". Another opinion is that the 448 bits limit is present to ensure that every bit of every subkey depends on every bit of the key,
F функциясы 32 биттік кірісті 8 биттік төрт бөлікке бөліп, осы бөліктерді S қораптарына кіріс ретінде пайдаланады. S қораптары 8 биттік кірісті қабылдап, 32 биттік шығыс береді. Шығыстар модуль 232 бойынша қосылып, содан соң XOR-далып, соңғы 32 биттік шығыс алынады (оң жақ жоғарғы бұрыштағы суретті қараңыз). 16-шы раундтан кейін соңғы алмастыру амалын кері қайтару және L-ді K18, ал R-ді K17-мен XOR-лау (шығысты ағарту). Шифрды жою шифрлеумен бірдей, тек P1, P2, …, P18 кері ретпен қолданылады. Бұл түсініксіз болуы мүмкін, себебі XOR амалы коммутативті және ассоциативті. Көптеген қате түсініктердің бірі – шифрлаудың кері ретін шифрды жою алгоритмі ретінде пайдалану (яғни, ең алдымен шифрленген мәтін блогына P17 және P18-ді XOR-лау, содан соң P жазбаларын кері ретпен пайдалану). Blowfish кілт кестесі P массиві мен S қораптарын pi сандарының ондық жүйедегі цифрларынан алынған мәндермен бастаудан басталады, онда ешқандай анық үлгі жоқ («жеңнен ештеңе шығармайтын» сан). Содан кейін құпия кілт, қажет болған жағдайда, кілтті циклмен қайталай отырып, байт бойынша барлық P жазбаларымен XOR-далады. 64 биттік нөлдік блок алгоритммен шифрланады. Нәтижесінде алынған шифрленген мәтін P1 және P2 жазбаларын алмастырады. Содан кейін осы шифрленген мәтін жаңа кіші кілттермен қайта шифрланады және жаңа шифрленген мәтін P3 және P4 жазбаларын алмастырады. Бұл жалғаса береді, барлық P массивін және барлық S қорабының жазбаларын алмастырады. Барлығында Blowfish шифрлау алгоритмі барлық кіші кілттерді жасау үшін 521 рет орындалады, шамамен 4 КБ дерек өңделеді. P массивінің ұзындығы 576 бит болғандықтан және кілт байттары инициализация кезінде осы 576 бит арқылы XOR-далатындықтан, көптеген іске асырулар кілт өлшемін 576 битке дейін қолдайды. Бұған себеп – 448 биттік кілттерді қолданатын Blowfish-тің бастапқы сипаттамасы мен 576 биттік кілттерді қолданатын анықтамалық іске асыру арасындағы қарама-қайшылық. Үшінші тараптың іске асыруларын тексеру үшін тест векторлары да 576 биттік кілттермен жасалды. Брюс Шнайерден қай Blowfish нұсқасы дұрыс екенін сұрағанда, ол былай деп жауап берді: «Бірыңғай нағыз Blowfish-ті анықтау үшін тест векторларын пайдалану керек». Басқа пікір бойынша, 448 биттік шектеу әр кіші кілттің әр биті кілттің әр битіне тәуелді екенін қамтамасыз ету үшін қажет.
Blowfish is a symmetric key block cipher, designed in 1993 by Bruce Schneier and included in many cipher suites and encryption products. Blowfish provides a good encryption rate in software, and no effective cryptanalysis of it has been found to date. However, the Advanced Encryption Standard (AES) now receives more attention, and Schneier recommends Twofish for modern applications. It is a 16 round Feistel cipher and uses large key dependent S boxes. In structure it resembles CAST 128, which uses fixed S boxes. The adjacent diagram shows Blowfish's encryption routine. Each line represents 32 bits. There are five subkey arrays: one 18 entry P array (denoted as K in the diagram, to avoid confusion with the Plaintext) and four 256 entry S boxes (S0, S1, S2 and S3). Every round r consists of 4 actions:
Action 1XOR the left half (L) of the data with the r th P array entryAction 2Use the XORed data as input for Blowfish's F functionAction 3XOR the F function's output with the right half (R) of the dataAction 4Swap L and R
The F function splits the 32 bit input into four 8 bit quarters and uses the quarters as input to the S boxes. The S boxes accept 8 bit input and produce 32 bit output. The outputs are added modulo 232 and XORed to produce the final 32 bit output (see image in the upper right corner). After the 16th round, undo the last swap, and XOR L with K18 and R with K17 (output whitening). Decryption is exactly the same as encryption, except that P1, P2, , P18 are used in the reverse order. This is not so obvious because xor is commutative and associative. A common misconception is to use inverse order of encryption as decryption algorithm (i. e. first XORing P17 and P18 to the ciphertext block, then using the P entries in reverse order). Blowfish's key schedule starts by initializing the P array and S boxes with values derived from the hexadecimal digits of pi, which contain no obvious pattern (see nothing up my sleeve number). The secret key is then, byte by byte, cycling the key if necessary, XORed with all the P entries in order. A 64 bit all zero block is then encrypted with the algorithm as it stands. The resultant ciphertext replaces P1 and P2. The same ciphertext is then encrypted again with the new subkeys, and the new ciphertext replaces P3 and P4. This continues, replacing the entire P array and all the S box entries. In all, the Blowfish encryption algorithm will run 521 times to generate all the subkeys about 4 KB of data is processed. Because the P array is 576 bits long, and the key bytes are XORed through all these 576 bits during the initialization, many implementations support key sizes up to 576 bits. The reason for that is a discrepancy between the original Blowfish description, which uses 448 bit keys, and its reference implementation, which uses 576 bit keys. The test vectors for verifying third party implementations were also produced with 576 bit keys. When asked which Blowfish version is the correct one, Bruce Schneier answered: "The test vectors should be used to determine the one true Blowfish". Another opinion is that the 448 bits limit is present to ensure that every bit of every subkey depends on every bit of the key,
Әлсіздігі және мұрагерлері
Blowfish-тің 64 биттік блок өлшемін пайдалануы (мысалы, AES-тің 128 биттік блок өлшеміне қарағанда) оны туған күн шабуылдарына, әсіресе HTTPS сияқты жағдайларда осал етеді. 2016 жылы SWEET32 шабуылы 64 биттік блок өлшемімен шифрларға қарсы ашық мәтінді қалпына келтіруді (яғни шифрланған мәтінді түсіндіруді) жүзеге асыру үшін туған күн шабуылдарын қалай қолдануға болатынын көрсетті. GnuPG жобасы Blowfish-ті 4 ГБ-тан үлкен файлдарды шифрлау үшін оның кішкентай блок өлшеміне байланысты пайдаланбауды ұсынады. Blowfish-тің азайтылған раунд нұсқасы, рефлективті әлсіз кілттерге белгілі ашық мәтіндік шабуылдарға ұшырауы мүмкін. Blowfish жүзеге асырулары 16 шифрлау раундысын қолданады және осы шабуылға ұшырамайды. Брюс Шнайер өзінің Blowfish-тің ізбасары Twofish-ке көшуді ұсынады.