关于零长度随机数对GCM和GMAC影响的注记
A Note on the Influence of a Zero Length Nonce on GCM and GMAC
浏览论文内容
中文总结 AI 辅助
本研究发现针对ISO/IEC版本GCM和GMAC的攻击,可通过零长度随机数恢复其哈希密钥以伪造任意密文或消息,该攻击不适用于NIST版本。
中文摘要 AI 辅助
在本注记中,我们展示了一种可通过零长度随机数(nonce)恢复GCM和GMAC哈希密钥的简单攻击方法。恢复哈希密钥后,攻击者可伪造任意密文或消息。我们注意到,ISO/IEC版本的GCM和GMAC允许随机数为零长度字符串,而NIST版本的GCM和GMAC明确要求随机数至少为1比特,因此我们的攻击适用于ISO/IEC版本,无法作用于NIST版本。
英文摘要
In this note, we show a simple attack that can recover the hash key of GCM and GMAC by using a zero length nonce. After recovering the hash key, the adversary can forge an arbitrary ciphertext or message as she wants. We note that the ISO/IEC version of GCM and GMAC allows the nonce to be a zero length string, while the NIST version of GCM and GMAC explicitly requires the nonce to be at least one bit. Hence, our attack works for the ISO/IEC version and cannot work for the NIST version.