38
A. Mileva et al.
schemes can be constructed from block ciphers (e.g., CBC-MAC (part of the
ISO/IEC 9797-1:1999 standard) or OCB-MAC [504]), from cryptographic hash
functions (e.g., HMAC (RFC 2104)), etc. Three lightweight security architectures
have been proposed for wireless sensor networks: TinySec [316], MiniSec [382] and
SenSec[370]. TinySec and MiniSec recommend CBC-MAC and the patented OCBMAC, while SenSec recommends XCBC-MAC, for which there is an existential
forgery attack [238], and all suggest the use of 32-bit tags. 32-bit security is not
enough—the recommended size is at least 64 bits.
Design choices for lightweight MACs include shorter tag sizes, simpler key
schedules, small hardware and/or software implementations, better performance
on very short messages, no use of nonces, and generation from lightweight block
ciphers and hash functions. Some lightweight MACs are listed in Table 2.8, and the
best known attacks against these MACs are provided in Table 2.9.
2.2.5 Authenticated Encryption Schemes
Authenticated encryption (AE) schemes combine the functions of ciphers and
MACs in one primitive, so they provide confidentiality, integrity, and authentication
of a given message. Besides the plaintext and the secret key, they usually accept
variable length Associated Data (AEAD schemes), a public nonce, and an optional
secret nonce. AD is a part of a message that should be authenticated, but not
encrypted.
Lightweight authenticated encryption schemes are presented in Table 2.10, and
the best known attacks against these schemes are provided in Table 2.11. Sablier
and SCREAM/iSCREAM are considered insecure. The hardware implementation
is given with encryption/authentication and decryption/verification functionalities.
2.3 Illustrative Issues in Security Evaluation of Certain
Encryption Schemes
As a consequence of the simplicity which makes them lightweight, the security
evaluation of lightweight encryption schemes arises as an issue of top importance. However, constraints on chapter space limit our discussion of the security
evaluation. Consequently, this section shows only a number of illustrative issues
relevant for the cryptanalysis of lightweight encryption techniques. In the first part, a
generic approach for security evaluation is discussed, and in the second an advanced
dedicated approach is pointed out.
Précédent

- 52/268

Suivant