4 ms·
Hi Jesse, So, let's talk about this point by point: 1. CTR mode and CBC mode both fulfil the same security definition: IND-CPA. IND part of the security defin
by samphippen 13y ago
Hi Jesse,
So, let's talk about this point by point:
1. CTR mode and CBC mode both fulfil the same security definition: IND-CPA. IND part of the security definition refers to the fact that: there exists no polynomially bounded attacker that can with probability better than a half distingiush which of two plaintexts (that the attacker choses) have been encrypted under the scheme. The CPA part refers to the fact that this is a chosen plaintext attack, and the polynomially bounded attacker may submit plaintexts for encryption.
CTR mode does not satisfy a stronger security definition than CBC mode, but is parallelizable for encryption and decryption. Whilst this may sound like it makes CTR mode preferable, it also means that each block of ciphertext is independent. With CBC mode, errors propogate throughout the ciphertext meaning that it is harder for an attacker which does have access to a encryption oracle to modify the message through modification of the ciphertext. They would have to be able to modify every block of the ciphertext in CBC mode, whilst having to only modify one in CTR Mode.
2. To clarify: all PID is encrypted under the strong AES encryption I have outlined above. In practical terms there is only one security definition that is stronger than the one we are using, which IND-CCA in which the attacker also has access to a decryption oracle. The attacker in this case is arbitrarily restricted to be unable to decrypt certain plaintexts. This does not make a large deal of sense in a real world attack, if the attacker does have access to a decryption oracle, it is likely they will be able to decrypt any ciphertext and blow the encryption wide open.
Regarding the necessity of encrypting PID, for various compliance reasons it is necessary for us to ensure that if someone pulls our servers out of the rack they can't get access to our users' data. This scheme satisfies our compliance requirements and, we believe, keeps our permission control model cryptographically enforced.
Thanks
--
Sam Phippen
How are you? Engineer.