UPDATE: Zenodo migration postponed to Oct 13 from 06:00-08:00 UTC. Read the announcement.

Conference paper Open Access

Substitution Attacks against Message Authentication

Armour, M.; Poettering, B.

This work introduces Algorithm Substitution Attacks (ASAs) on message authentication schemes. In light of revelations concerning mass surveillance, ASAs were initially introduced by Bellare, Paterson and Rogaway as a novel attack class against the confidentiality of encryption schemes. Such an attack replaces one or more of the regular scheme algorithms with a subverted version that aims to reveal information to an adversary (engaged in mass surveillance), while remaining undetected by users. While most prior work focused on subverting encryption systems, we study options to subvert symmetric message authentication protocols. In particular we provide powerful generic attacks that apply e.g. to HMAC or Carter–Wegman based schemes, inducing only a negligible implementation overhead. As subverted authentication can act as an enabler for subverted encryption (software updates can be manipulated to include replacements of encryption routines), we consider attacks of the new class highly impactful and dangerous.

Files (509.6 kB)
Name Size
29-Substitution Attacks against Message Authentication.pdf
md5:51027133289b7e901dab87979d0c977c
509.6 kB Download
81
46
views
downloads
All versions This version
Views 8181
Downloads 4646
Data volume 23.4 MB23.4 MB
Unique views 7878
Unique downloads 4646

Share

Cite as