From Known-Plaintext Security to Chosen-Plaintext Security
Ivan B. Damgård
November 2001 |
Abstract:
We present a new encryption mode for block ciphers. The mode is
efficient and is secure against chosen-plaintext attack (CPA) already if the
underlying symmetric cipher is secure against known-plaintext attack (KPA).
We prove that known (and widely used) encryption modes as CBC mode and
counter mode do not have this property. In particular, we prove that CBC mode
using a KPA secure cipher is KPA secure, but need not be CPA secure, and we
prove that counter mode using a KPA secure cipher need not be even KPA
secure. The analysis is done in a concrete security framework
Available as PostScript, PDF, DVI. |