A new method for format preserving encryption in high-data rate communications
Autor: | M. Garcia-Bosque, A. Perez-Resa, Carlos Sánchez-Azqueta, Santiago Celma |
---|---|
Rok vydání: | 2020 |
Předmět: |
General Computer Science
Computer science 0211 other engineering and technologies 02 engineering and technology Encryption 0202 electrical engineering electronic engineering information engineering FPE (format preserving encryption) General Materials Science Chosen-plaintext attack Field-programmable gate array Stream cipher Block cipher 021110 strategic defence & security studies business.industry 020208 electrical & electronic engineering Advanced Encryption Standard General Engineering Codebook FPGA (field programmable gate array) Adversary stream cipher Ethernet Format-preserving encryption lcsh:Electrical engineering. Electronics. Nuclear engineering business lcsh:TK1-9971 Computer hardware |
Zdroj: | Zaguán. Repositorio Digital de la Universidad de Zaragoza instname Zaguán: Repositorio Digital de la Universidad de Zaragoza Universidad de Zaragoza IEEE Access, Vol 8, Pp 21003-21016 (2020) |
Popis: | In some encryption systems it is necessary to preserve the format and length of the encrypted data. This kind of encryption is called FPE (Format Preserving Encryption). Currently, only two AES (Advanced Encryption Standard) modes of operation recommended by the NIST (National Institute of Standards and Technology) are able to implement FPE algorithms, FF1 and FF3. These modes work in an electronic codebook fashion and can be configured to encrypt databases with an arbitrary format and length. However, there are no stream cipher proposals able to implement FPE encryption for high data rate information flows. The main novelty of this work is a new block cipher operation mode proposal to implement an FPE algorithm in a stream cipher fashion. It has been called CTR-MOD and it is based on a standard block cipher working in CTR (Counter) mode and a modulo operation. The confidentiality of this mode is analyzed in terms of its IND- CPA (Indistinguishability under Chosen Plaintext Attack) advantage of any adversary attacking it. Moreover, the encryption scheme has been implemented on an FPGA (Field Programmable Gate Array) and has been integrated in a Gigabit Ethernet interface to test an encrypted optical link with a real high data rate traffic flow. |
Databáze: | OpenAIRE |
Externí odkaz: |