3 ms·
We present practical attacks against OCB2 an ISO-standard authenticated encryption (AE) scheme. OCB2 is a highly-efficient blockcipher mode of o
by erwan 8y ago
We present practical attacks against OCB2
an ISO-standard authenticated encryption (AE) scheme.
OCB2 is a highly-efficient blockcipher mode of
operation. It has been extensively studied and widely
believed to be secure thanks to the provable security
proofs.
Our attacks allows the adversary to create forgeries
with (almost-known) single encryption query.
What I find most fascinating is that OCB2 is a scheme for which there has been a security proof since 2003. I am neither a cryptographer nor up-to-date with the state of the art in cryptanalysis, but at first glance, it seems like most attacks discovered these days rely on some kind of side channel or unspecified aspects of the protocol that the implementations get wrong. Even djb (cryp.to) is spooked: https://twitter.com/hashbreaker/status/1057791485016526848 https://twitter.com/hashbreaker/status/1057791485016526848
- AnimalMuppet 8y agoSo the proof is erroneous, or it doesn't prove what it was thought to prove, or the attack uses a technique that doesn't fall within the scope of the proof - or else the attack doesn't actually work. Still terrifying. What other proofs of security and/or correctness are false and/or don't prove what we think they do?
- kpcyrd 8y agoFor anybody else wondering about the reply to that tweet: mosh is using AES-OCB, but seems to be using OCB3 from what I can tell: https://github.com/mobile-shell/mosh/blob/944fd6c796338235c4f3d8daf4959ff658f12760/src/crypto/ocb.cc https://github.com/mobile-shell/mosh/blob/944fd6c796338235c4...
- tptacek 8y agoIt would be more surprising to find open-source crypto that used OCB2 at all than it would be to find open-source crypto that was practically vulnerable to this attack. The open source patent release for OCB is younger than OCB3.
- keithwinstein 8y agoYes, Mosh definitely uses OCB3 and is apparently unaffected (just added a FAQ to the website). Still pretty scary though -- this could easily have been Mosh's first real security vulnerability and it would have sucked. We first implemented Mosh's crypto in 2011, shortly after OCB3 was released. If I had started working on Mosh six months earlier, I probably would have picked OCB2.
- tptacek 8y agoI haven't though carefully about this at all, but, if Mosh had used "vanilla" OCB2, would it have been practically vulnerable to this attack? What would be the circumstances?
- loeg 8y agoWhat reasons lead you to select any OCB variant in 2011? Not trying to be snarky -- I am genuinely curious, given the patent landscape at that time and lack of any open source grant.
- keithwinstein 8y agoReasonable question! (1) OCB has long had a patent grant for GPLed software (https://github.com/mobile-shell/mosh/blob/master/ocb-license.html https://github.com/mobile-shell/mosh/blob/master/ocb-license...), so the Rogaway patents were a non-issue even in 2011. (Of course there are other patents on authenticated encryption, e.g. IBM's Jutla patents. I understand why OCB gets singled out because of the Rogaway patents, but my understanding is that all AE modes, and perhaps most computer programs in general, likely implicate some patent.) (2) The crypto experts told us that OCB was the best AEAD mode and that if we are going to put all our eggs in one basket, we should pick OCB. I am pretty happy with the choice and with the lack of traditional cipher negotiation in Mosh. (3) Implementation quality strongly favored OCB. At the time, OpenSSL had no AE modes at all, so we probably would have had to vendor and ship an implementation of something not-OCB, or use a non-AE construction. I understand OpenSSL had a lot of pain implementing GCM in a robust way over the subsequent years -- if we had depended on OpenSSL or tried to use its AE modes, we would have inherited that pain. Given our position of wanting to pick one mode and lock it in (which seems to have paid off), I don't think we could have made a better choice in 2011 than AES-OCB. I might make the same choice today, but would look harder at the other available AE modes in OpenSSL.