Введение
Гибкость — это свойство некоторых криптографических алгоритмов. Алгоритм шифрования считается "гибким", если возможно преобразовать шифротекст в другой шифротекст, который при дешифровании даст связанный открытый текст. То есть, имея шифротекст, полученный из открытого текста , можно сгенерировать другой шифротекст, который при дешифровании даст , для известной функции , не обязательно зная или узнавая .
Malleability is often an undesirable property in a general purpose cryptosystem, since it allows an attacker to modify the contents of a message. For example, suppose that a bank uses a stream cipher to hide its financial information, and a user sends an encrypted message containing, say, "." If an attacker can modify the message on the wire, and can guess the format of the unencrypted message, the attacker could change the amount of the transaction, or the recipient of the funds, e. g. "". Malleability does not refer to the attacker's ability to read the encrypted message. Both before and after tampering, the attacker cannot read the encrypted message. On the other hand, some cryptosystems are malleable by design. In other words, in some circumstances it may be viewed as a feature that anyone can transform an encryption of into a valid encryption of (for some restricted class of functions ) without necessarily learning Such schemes are known as homomorphic encryption schemes. A cryptosystem may be semantically secure against chosen plaintext attacks or even non adaptive chosen ciphertext attacks (CCA1) while still being malleable. However, security against adaptive chosen ciphertext attacks (CCA2) is equivalent to non malleability.
Гибкость часто является нежелательным свойством в криптосистеме общего назначения, поскольку она позволяет злоумышленнику изменять содержимое сообщения. Например, предположим, что банк использует поточный шифр для защиты своей финансовой информации, и пользователь отправляет зашифрованное сообщение, содержащее, скажем, "100". Если злоумышленник может изменить сообщение в процессе передачи и угадать формат незашифрованного сообщения, он может изменить сумму транзакции или получателя средств, например, на "". Гибкость не относится к способности злоумышленника прочитать зашифрованное сообщение. Как до, так и после изменения, злоумышленник не может прочитать шифротекст. С другой стороны, некоторые криптосистемы изначально разработаны как гибкие. Другими словами, в некоторых случаях это может рассматриваться как полезная функция, позволяющая любому преобразовать шифротекст в действительный шифротекст (для некоторого ограниченного класса функций) без необходимости узнавать . Такие схемы известны как схемы гомоморфного шифрования. Криптосистема может быть семантически устойчива к атакам с выбранным открытым текстом или даже к неадаптивным атакам с выбранным шифротекстом (CCA1), при этом оставаясь гибкой. Однако устойчивость к адаптивным атакам с выбранным шифротекстом (CCA2) эквивалентна негибкости.
Malleability is often an undesirable property in a general purpose cryptosystem, since it allows an attacker to modify the contents of a message. For example, suppose that a bank uses a stream cipher to hide its financial information, and a user sends an encrypted message containing, say, "." If an attacker can modify the message on the wire, and can guess the format of the unencrypted message, the attacker could change the amount of the transaction, or the recipient of the funds, e. g. "". Malleability does not refer to the attacker's ability to read the encrypted message. Both before and after tampering, the attacker cannot read the encrypted message. On the other hand, some cryptosystems are malleable by design. In other words, in some circumstances it may be viewed as a feature that anyone can transform an encryption of into a valid encryption of (for some restricted class of functions ) without necessarily learning Such schemes are known as homomorphic encryption schemes. A cryptosystem may be semantically secure against chosen plaintext attacks or even non adaptive chosen ciphertext attacks (CCA1) while still being malleable. However, security against adaptive chosen ciphertext attacks (CCA2) is equivalent to non malleability.
Примеры криптосистем с поддающейся коррекции
В потоковом шифре шифротекст создается путем применения операции исключающего ИЛИ к открытому тексту и псевдослучайному потоку, основанному на секретном ключе, поскольку противник может построить шифрование любого сообщения для любого ключа, как в криптосистеме RSA, где открытый текст шифруется как , а является открытым ключом. При наличии такого шифротекста противник может создать шифрование любого сообщения для любого ключа, как. По этой причине RSA обычно используется вместе с методами заполнения, такими как OAEP или PKCS1. В криптосистеме ElGamal открытый текст шифруется как , где является открытым ключом. При наличии такого шифротекста противник может вычислить , что является допустимым шифрованием для любого . В отличие от этого, система Cramer-Shoup (которая основана на ElGamal) не является податливой к изменению. В криптосистемах Paillier, ElGamal и RSA также возможно объединить несколько шифротекстов полезным образом для получения связанного шифротекста. В Paillier, имея только открытый ключ и шифрования и , можно вычислить допустимое шифрование их суммы. В ElGamal и RSA можно объединить шифрования и для получения допустимого шифрования их произведения.
In the RSA cryptosystem, a plaintext is encrypted as , where is the public key. Given such a ciphertext, an adversary can construct an encryption of for any , as For this reason, RSA is commonly used together with padding methods such as OAEP or PKCS1. In the ElGamal cryptosystem, a plaintext is encrypted as , where is the public key. Given such a ciphertext , an adversary can compute , which is a valid encryption of , for any In contrast, the Cramer Shoup system (which is based on ElGamal) is not malleable. In the Paillier, ElGamal, and RSA cryptosystems, it is also possible to combine several ciphertexts together in a useful way to produce a related ciphertext. In Paillier, given only the public key and an encryption of and , one can compute a valid encryption of their sum In ElGamal and in RSA, one can combine encryptions of and to obtain a valid encryption of their product
Block ciphers in the cipher block chaining mode of operation, for example, are partly malleable: flipping a bit in a ciphertext block will completely mangle the plaintext it decrypts to, but will result in the same bit being flipped in the plaintext of the next block. This allows an attacker to 'sacrifice' one block of plaintext in order to change some data in the next one, possibly managing to maliciously alter the message. This is essentially the core idea of the padding oracle attack on CBC, which allows the attacker to decrypt almost an entire ciphertext without knowing the key. For this and many other reasons, a message authentication code is required to guard against any method of tampering.
Блок-шифры в режиме шифрования блоками с цепочкой, например, частично податливы к изменению: изменение бита в блоке шифротекста полностью исказит открытый текст, который он расшифровывает, но приведет к изменению того же бита в открытом тексте следующего блока. Это позволяет злоумышленнику "пожертвовать" одним блоком открытого текста, чтобы изменить данные в следующем блоке, возможно, злонамеренно изменив сообщение. Это, по сути, основная идея атаки на CBC с использованием оракула дополнения, которая позволяет злоумышленнику расшифровать почти весь шифротекст, не зная ключа. По этой и многим другим причинам необходим код аутентификации сообщений для защиты от любых попыток вмешательства.
In the RSA cryptosystem, a plaintext is encrypted as , where is the public key. Given such a ciphertext, an adversary can construct an encryption of for any , as For this reason, RSA is commonly used together with padding methods such as OAEP or PKCS1. In the ElGamal cryptosystem, a plaintext is encrypted as , where is the public key. Given such a ciphertext , an adversary can compute , which is a valid encryption of , for any In contrast, the Cramer Shoup system (which is based on ElGamal) is not malleable. In the Paillier, ElGamal, and RSA cryptosystems, it is also possible to combine several ciphertexts together in a useful way to produce a related ciphertext. In Paillier, given only the public key and an encryption of and , one can compute a valid encryption of their sum In ElGamal and in RSA, one can combine encryptions of and to obtain a valid encryption of their product
Block ciphers in the cipher block chaining mode of operation, for example, are partly malleable: flipping a bit in a ciphertext block will completely mangle the plaintext it decrypts to, but will result in the same bit being flipped in the plaintext of the next block. This allows an attacker to 'sacrifice' one block of plaintext in order to change some data in the next one, possibly managing to maliciously alter the message. This is essentially the core idea of the padding oracle attack on CBC, which allows the attacker to decrypt almost an entire ciphertext without knowing the key. For this and many other reasons, a message authentication code is required to guard against any method of tampering.
Полная непластичность
Фишлин в 2005 году определил понятие полной невосприимчивости к изменению как способность системы сохранять эту невосприимчивость, даже если злоумышленнику предоставляется возможность выбрать новый открытый ключ, который может быть функцией исходного открытого ключа. Иными словами, злоумышленник не должен иметь возможности создать шифротекст, в котором исходный открытый текст связан с исходным сообщением отношением, учитывающим также открытые ключи.