|
On the security aspects of protocol CRISP
V. A. Kiryukhinab a LLC «SFB Lab»
b JSC «InfoTeCS», Moscow
Abstract:
Using the provable security approach, we analyze CRISP – a standardized Russian cryptographic protocol that aims to ensure confidentiality, integrity of transmitted messages, as well as protection against replay attacks. The main features of the protocol are non-interactivity, multicasting, and dynamic selection of a cipher suite. The protocol is considered as a specific mode of authenticated encryption with associated data (AEAD). We take into account that one key can be used by many protocol's participants and in different cipher suites. We impose requirements for the set of the cipher suites used in the protocol and show that the existing ones meet them. The security of the protocol is reduced to the PRF-security of KDF and to the security of AEAD-algorithms in all cipher suites. For the protocol with existing cipher suites, only the PRP-security of the «Magma» cipher is required. We obtain heuristic estimates for this computational problem using existing attacks on «Magma». Estimates of the maximum allowable amount of data processed using a single key are also given for existing cipher suites.
Key words:
CRISP, provable security, AEAD, Magma.
Received 01.IX.2023
Citation:
V. A. Kiryukhin, “On the security aspects of protocol CRISP”, Mat. Vopr. Kriptogr., 15:1 (2024), 57–81
Linking options:
https://www.mathnet.ru/eng/mvk462https://doi.org/10.4213/mvk462 https://www.mathnet.ru/eng/mvk/v15/i1/p57
|
Statistics & downloads: |
Abstract page: | 134 | Full-text PDF : | 26 | References: | 20 | First page: | 10 |
|