On the (in)security of two Joint Encryption and Error Correction schemes
by Qi Chai; Guang Gong
International Journal of Security and Networks (IJSN), Vol. 6, No. 4, 2011

Abstract: Joint Encryption and Error Correction (JEEC) is proposed to combine encoding/encryption as one process to boost more compact implementations. In this paper, we provide rigorous investigation on the security of two JECC schemes, namely ECBC and SECC. For ECBC, we found a 3-stage differential-like attack, which breaks it with O(k × 2deg(f) + 2k) effort, where deg(f) is the degree of the core cryptographic function f and k is the block length. For SECC, we found a similar attack of complexity O(k × 2k+1). Additionally, we exhibit that f used in ECBC is particularly vulnerable, which allows the secret matrix to be recovered in O(1). To mitigate this vulnerability, we propose a secure-yet-lightweight construction of f. Finally, the core part of our attack has been implemented. Experimental results confirm that the original implementation of ECBC can be broken in constant time (<0.4 s) regardless of k, whereas the ECBC enhanced by our proposed f can withstand this attack to the maximum extent.

Online publication date: Tue, 31-Jan-2012

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Security and Networks (IJSN):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com