Re: [CFRG] Comment on AES-GCM-SST

John Mattsson <john.mattsson@ericsson.com> Mon, 06 May 2024 14:41 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A6B13C14F6BF for <cfrg@ietfa.amsl.com>; Mon, 6 May 2024 07:41:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.666
X-Spam-Level:
X-Spam-Status: No, score=-2.666 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.669, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2Dl5aHu7I7qT for <cfrg@ietfa.amsl.com>; Mon, 6 May 2024 07:41:46 -0700 (PDT)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on20601.outbound.protection.outlook.com [IPv6:2a01:111:f403:2612::601]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5F311C151068 for <cfrg@irtf.org>; Mon, 6 May 2024 07:41:46 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NGU9aJXJGf3Q9HhrmD3kY/tiYwlvNt0mcXvrnqhim/OGuncyfN8VOcf3loOeNzmhRBUwLyVzchcjUdYZbNBlzT9pBl421E5UUhnt26TyhaMFyQxDSEBkhDwfwaTWKZ/i8d0aN81KTXHF5Qb9WxCtRvQqdQRJqhqUCyps9tNAKZTvjd2Z20UKOkbcAGBOOG7zuumdkKHeyAWCswCUa7n5nzR53sQadvY2gNCvXji8i5TrFXOsAR0cSHPx1MoNKGcyrc16T2lwEuXjfNRkWEPbIqNtESy60iaXdcklg0S0DSkGKiLTUm7BK3dC14N4viT4xYR1t89OPFUoywDyDSnENg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ogVW0t3By0PrrhMqHFknKqdhHxer8cn+JIF6EenuqHo=; b=BKL06IlCFLD0req28QEe2FOu/LASiResEYK9M1kGryz/2VkJb7Kr+HfNJJGLQtf8Pg8ciTHxBtHR2uPWFpLIJJnrIGvmBROBP9uJCzXd7f1Q2OjH9CgEsy0HooBJWRVQyKz8LRj/qtEGDR/pkZAxl47sFdG7lSg0SnpbL/ocEQpYecW6hFuVGgARJJ+j7MWYkMFuZ2Bb/ARbDhSARSl5rGmwZ4VQjNtCHwiHp2058m+gg+q4m2fWnlfbYM18txE/UzI7+zMdn8V0Y3Lj8RbL3VJWNMofG6Jz2oNsc1ZVjnH7h0S5gUyN6Ikd0VRqOACdKdNkusEXFLGjHlcxNIkGDQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ogVW0t3By0PrrhMqHFknKqdhHxer8cn+JIF6EenuqHo=; b=F/isfOwYgq/JNrSn5Sr4yopsAwBeUNHwDoDarZAXMVtsyhz5WYKc7LAx0qIZlmjdTDpkkbCK/WGEfrPUa1DFSs3Lt69m3ke8cOG0uVvhy+Z686BOMDjTZ8wEIUeye9Tb6JD6tzjq+W6fveIO1FQmXHb7Q25QyBmcys1Lv8uhY0CTpHGj2eb7/5H9sLaL4vQGdwj0KxbZ9a6p5ilegd9z83Yg2N/vLqhJO48oQSKoytTw/ZSUCALfMvgU/kE0acQtaVkCA57Amu8lgiTcMVMO1FogyWta752Qe+2tyGlHIAqGTI34EA03ZJUHIq4pmw2THIf6w4LvAw4VwjdPikFsDw==
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by AS8PR07MB7877.eurprd07.prod.outlook.com (2603:10a6:20b:39a::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7544.41; Mon, 6 May 2024 14:41:42 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8%3]) with mapi id 15.20.7544.041; Mon, 6 May 2024 14:41:42 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Yehuda Lindell <yehuda.lindell@gmail.com>, "Scott Fluhrer (sfluhrer)" <sfluhrer=40cisco.com@dmarc.ietf.org>, "cfrg@irtf.org" <cfrg@irtf.org>
Thread-Topic: [CFRG] Comment on AES-GCM-SST
Thread-Index: AQHanvPyVEDIfwg2+UCWqI2GZMCRQrGKOKKAgAAPRsM=
Date: Mon, 06 May 2024 14:41:41 +0000
Message-ID: <GVXPR07MB9678F598C96A3CA68C47428F891C2@GVXPR07MB9678.eurprd07.prod.outlook.com>
References: <85926AD9-298F-47BB-93F5-0B6D8D180D80@gmail.com> <CH0PR11MB54441BD2D75B084A56D67B83C11C2@CH0PR11MB5444.namprd11.prod.outlook.com>
In-Reply-To: <CH0PR11MB54441BD2D75B084A56D67B83C11C2@CH0PR11MB5444.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|AS8PR07MB7877:EE_
x-ms-office365-filtering-correlation-id: 758e1a7f-c50b-41b9-48a9-08dc6ddaa51b
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0; ARA:13230031|1800799015|376005|366007|38070700009;
x-microsoft-antispam-message-info: fNQ783Pr7jsVX8b4wFaBEvTEDf1to9JeBx8mCobPAm5bfwmwY+bMI3Cs60HdLVXb1FlFkwg+CcHzrPP/A+4IKTiCTixQUxu6QTw0DTGxXArpYS+gMAuxjN9cNcHoXguq5uUVMgc9IsoczucEsKMSjM1lZ2xgyxMvDqhEv8aiqEvBF8DRo/Q+cvWtza3dQU9xMjglnZHuYMPgn2V4jhAi23xb1W+n+huEeHNq+nLIq7fWdL/n6fLnCaM0vCVuj413Xx8/ESyil+W2n9kxxJYEPsaACMw/44fhW/QrbAJPrZfLC20Oq5wjBU1pJsCohHmNq8Gig2BomyJ8g5xqSiuKCsKecZGCg0Mtsrt6BVxRqY5vYUj0OBCSGEm6MeDoK9qzmKLeCDrlyAeKIzJY5yOSJNJykNT1mQUrawuH1DeR6pbmCDnxZjZ+XkPV0IBOpcuK1g8ZThsWPXLNZvai7LqrJ6zCUtXxn8X/9MdFRFkUqs1CihCUBju7u7urI+Aw2nvAsEsdCD8+WDbwcWSD8hmAX/EMUmBLqWDnRIqnkaXVaeUA3K9BhQSR/eJWQbos9mkokzuxiE1bSx+2MEirSXX1yOC4j02vH7CCIRS7oYsp0MCFz5CFokmkM0VhtL7wjhTK0uim1n2Lb2dOrgO4Zh8Dcydhtc9ZGsbT6Um/QVgf4d8s4LtSa77hiKOaGPuJT8ot5JRfffzeUpWc8Q3wrr9yn5bnkTZIaOcUOqLfBcnQGQFdtmjS5k3k2fcN8BKe4Ocb/aFGOLMR5uZqjrq4v9dm0JRw6toIZpNhRKteWM1Npzo8SUOuimRgr4+i5U7lIB9eoYDPvutNtRT51OGx7dKmrT6tortfHWXEyjR76dSVd/R3K5+0AsCOWYysw8aqHuH5k2tPxBrT4HLkztUeQUUjnZ3oA4ZM0rYVKfRCdB1pFKvP1wUBQllPf3YEmHVe3XARs3VMZ9bhmNTSE+0DNxoDXV+0HkyqkY5ex3AhFd1lMD/UB6KiozRQJ6I0vtFrr9BE3gDum0koI/2vdRJfc9zZ2lKEq+rSuC3BwBABtj5aCcnjyEvjkx8xLonuK63GHBfq7QpgXVnV6Yr39gFC1GE7qqeVbTJVG4jaTgtaZVMzeZhkJcmkjabx3EyiU/scEgo/hkzJtsEHmFBETeGg//N2y75zPmLZU+r4yInXbYPzKzNL30Lh+SYE1Hh8Cemh/0spxuI2Vowg1H861Lan4S3luLaxfuU595SWtlW22BAqUUvIsUw9pvEiRAwI9El+18LP138hzosvWqBmMayB9/MjHQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVXPR07MB9678.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(1800799015)(376005)(366007)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: CQHYK6Ih0eNb940pC2LCVEg19c5jjLJmGBpIx1Tjc1otNHOy/gG6fStPPVJKSsEM4ONmEzQjGYkmuyiGD9U9JBkiVvNexI+neNN8iBMbFq55iMXOXtJCm2iX9NEJv7rDtIVMP8750MbF7jEnMJ36ipLTbTyinZ4YxC4i3LnXb5pBpgc/UFia7/YKdV+Z8YDay6QN9pIIBH5S7OjanXpitIvKG3hk9oqdyhFlyb9A/l2i+B3Q9jx1dAeDeSSUbx5BuWUI7SJxlTjJlim3aHKPAqK99M3LszSbKGTvtTRLkntUgPyXZN4X8TSd0NftxNsg1q5B4XX/zCnSHGaN99z+Sbt05AAWeC4oMaU8DehpJBE9xg0PCzSHcGoMEbkYLpd5GKSF3HXy3r4UGrxvP4iNa4iiRgrtzEpzyw9dlFdxGvWHq4q0CYyw6oXlRraAbljq61Evl3Ybek2sGnIN1vtZANDXYGdhf/yo4oECWmx+4f/0Ni5uVD+ASSJsb5plsWR/QnENT4YzAW76u4UtU5saxq8KCLAmhdKcMg6ooz3Jk+Y1bn5TD9DPGYaFuXavrpBcvNMwpMezIimvSq8irW++l5LqRClkqD16CtWoMiDVojxF0Lal4J5cvfI5AdQtYS9hPnuMlO3/ezceKg4oXi6C13qmIAkUe7XF+JdvuXFAg3RhDyx4A6n36+vVcMTJtKOarLoSlVSadp5ltMHAkZbj+sYWXAX51Xd9/H/DqJyzFvBqUhOiR7Kksj4wU0auvYsTgpkHAR4CjpgNL1N5ApTUhkwKdrmsLPKmXtJcYtNhTRfl30Yy+RYu02lyxP7FloBGkzvJQz5nsx961wQigtYha7UGtwdKyIFoVuXqA1bGpmgNL7krrmbjy70Rk3dmpGE2API6zo8+jRLnz5zYYMy6J2GEyNac0oa87rpkzRA1O8/pHmr7BJH0GlgF+o4KdoYOBx6hI4Be5/K/7ISPCmweQX/yIwLGjBxdEMQfG3tUygmm16zRi/fwKgDKf86JgBJ9uQi5pGeSOCY7hF/VUi2TiNU/fr4GhACPiFwxT3O3x1ZZ/eodjj4ome6hriJa213CRCFRxU3v4dr0E1sqEFHyGdERC6udL08WCd8dv4496VZxsLLUyVgIKW8VMCnTHpKBukSovENqfVkgBcHqqtltr8yevayPKp7Tohym17QlWb61dOMj81ve2eIzm1QgML0jFid7zEddX5iSZQtkbJMhvuC/UFwE1CM1hSlQGf4nY/GvIffgaCvL0nKjAJy5dE24UxZ5EPO5XF6V7SW9IDUi7Dk+cKGoNEc4nHVbQDTLjyLzKfuHzjgxizltRhAQK5P8jDTkUwVlBuwQh5H7Yd3NDmWc1xU7joVQn55ZK8jGO645xZmYzBBIo3fdNj3PLMY8n9kUXhCZD6LBMPj8lDx7t+fQxx6dB5q/rxy6AbkKcD3pwOXaOdKLDde9Bz1DDJw82pRq3XsPQpuh9DJWbhdJw4yMCjc6NkiWj4ptU3+TiSNdnhygijUYnC+81LnfNP5XFtBdfzKUUWhREJf5fBpYA5e8hV4OqknF/OHHCBkZ803UyrN903dDI/JA8goKnVFLvWnaalTfFytfZG0ecQ0REp1nGcwqtM/B62tua/kZueI=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB9678F598C96A3CA68C47428F891C2GVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 758e1a7f-c50b-41b9-48a9-08dc6ddaa51b
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 May 2024 14:41:41.9558 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: +S4whFDZSfByMs+rZI0H299zrkw40VPmpqyp5Ne8HGqWQZb2tQXw6v4iomeoi//fA7uQak0jkBJwSTxzv7ICgBzGvT5wCYtIrcUci0fM6aE=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR07MB7877
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/V5udPNVLJXhHI5Z3D6voOJISa38>
Subject: Re: [CFRG] Comment on AES-GCM-SST
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://mailman.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://mailman.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 May 2024 14:41:50 -0000

Hi Yehuda,

Thanks for the analysis.

I have not looked into the details of solving the suggested equations but it seems like the attack idea relies on the decryption function allowing nonce reuse. I.e., the attack is not possible when GCM-SST is used in a security protocol with replay protection, which is how it is intended to be used in mobile systems and media encryption. I think the problem goes away if a requirement is added that the nonces in both the encryption and decryption function must be unique. As long as the decryption function rejects nonces that has sucessfully been decrypted before, a single forgery does not help with multi-forgery as the the subkeys from one nonce does not help the attacker to get subkeys for other nonces.

Cheers,
John

From: CFRG <cfrg-bounces@irtf.org> on behalf of Scott Fluhrer (sfluhrer) <sfluhrer=40cisco.com@dmarc.ietf.org>
Date: Monday, 6 May 2024 at 15:43
To: Yehuda Lindell <yehuda.lindell@gmail.com>, cfrg@irtf.org <cfrg@irtf.org>
Subject: Re: [CFRG] Comment on AES-GCM-SST
I believe this attack needs to be rewritten a bit before it works.

The issue is that X is a function of the message; X is a complex function of the message.  You could recover the truncated tag (and hence some information on Q*X) for a single message, however once you switch to another message, X changes.

A more correct way of stating it is to expand T to:
        T = Q * H * S[z-1] + Q * H^2 * S[z-2] + const
Where the attacker modifies S[z-1], S[z-2] (the last two message blocks) and keeps everything else (other than the guessed tag) constant.  Fortunately, H^2 is a bitwise linear function of H, and so the original attack based on expanding quadratic terms still works (and once the attacker recovers H, Q for this nonce, it's game over).

On the other hand, we should remember that this O(2^40) attack involves throwing 2^40 messages at the decryptor (and the vast majority of them will be rejected as invalid).  This is considerably more difficult than, say, breaking 40 bit DES given a plaintext/ciphertext pair; we need to assume that the device under attack won't realize that, after a massive number of decryption failures, that something is up.  We might not want to make such an assumption on the application, however we should be aware of the difference between an attack that the attacker can perform on his own, and one where he needs to interact with a legitimate party...

> -----Original Message-----
> From: CFRG <cfrg-bounces@irtf.org> On Behalf Of Yehuda Lindell
> Sent: Sunday, May 5, 2024 9:55 AM
> To: cfrg@irtf.org
> Subject: [CFRG] Comment on AES-GCM-SST
>
> I've taken a look at AES-GCM-SST, and have a couple of comments.
>
> First, I think that I have found another attack that doesn't require nonce-
> reuse. It has a higher complexity but as stated works without nonce reuse,
> and provides key extraction and thus a universal forgery.
>
> By the standard,
>
> X = POLYVAL(H, S[0], S[1], ..., S[m + n - 1]) T = POLYVAL(Q, X XOR S[m + n]) XOR
> M
>
> The POLYVAL in computing T is a single multiplication, and so we have T = Q *
> (X XOR S[m+n]) XOR M = Q * X + Q * S[m+n] + M
>
> For the same nonce (and the attacker can always use the same nonce) and
> same-length messages, it follows that Q * S[m+n] + M is constant, and
> therefore it remains to learn Q * X. This is a quadratic equation with 128
> variables and so can be rewritten as a linear equation with 128-choose-2 ~
> 2^13 new variables.
>
> Consider a 32-bit tag. In each equation with tag=0 we obtain 32=2^5 linear
> equations. Therefore we need 2^8 such equations. Each equation takes
> expected 2^32 queries, and therefore with expected 2^40 queries we can
> learn the key, and from then on forge any message desired.
>
> Therefore the standard doesn't meet its stated goal which is to achieve
> forgery probabilities close to ideal. Specifically, although it should be possible
> to forge a single message with 2^32 queries, it should not be possible to
> obtain a universal forgery in time 2^40.
>
> As a second comment, in general, I believe that a proposal for a mode of
> operation that aims to achieve something like the above needs to have a full
> proof of security with concrete bounds. Otherwise we can expect to cat-and-
> mouse finding and fixing attacks, like the one described by Scott Fluhrer and
> the one above.
>
> Best,
>
> Yehuda
> _______________________________________________
> CFRG mailing list
> CFRG@irtf.org
> https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailman.irtf.org%2Fmailman%2Flistinfo%2Fcfrg&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C44c2f762c8074bb1b7c808dc6dd273f9%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C638505997859334216%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=3WDmJA07tiAAAqpxJHxyx4Z96EueRQ1FFLlqd3vu4cU%3D&reserved=0<https://mailman.irtf.org/mailman/listinfo/cfrg>

_______________________________________________
CFRG mailing list
CFRG@irtf.org
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailman.irtf.org%2Fmailman%2Flistinfo%2Fcfrg&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C44c2f762c8074bb1b7c808dc6dd273f9%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C638505997859341664%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=Cub0LO4C9XjszrMOdRT0UQxxZFcS6jpBZBYrxiwjvn4%3D&reserved=0<https://mailman.irtf.org/mailman/listinfo/cfrg>