A concrete security treatment of symmetric encryption

Mihir Bellare, Anand Desai, E. Jokipii, Phillip Rogaway

2002 · 914 citations · 12 references

Concepts

TL;DR

Symmetric encryption is examined within a concrete security framework. The study defines four notions of chosen‑plaintext security, analyzes reductions among them, and classifies the notions as stronger or weaker in concrete terms. Concrete‑security reductions are derived, and the authors analyze block‑cipher encryption methods, including CBC, to assess their security. Tight upper and lower bounds on adversary success are established, demonstrating the relative strengths of the notions.

Abstract

We study notions and schemes for symmetric (ie. private key) encryption in a concrete security framework. We give four different notions of security against chosen plaintext attack and analyze the concrete complexity of reductions among them, providing both upper and lower bounds, and obtaining tight relations. In this way we classify notions (even though polynomially reducible to each other) as stronger or weaker in terms of concrete security. Next we provide concrete security analyses of methods to encrypt using a block cipher, including the most popular encryption method, CBC. We establish tight bounds (meaning matching upper bounds and attacks) on the success of adversaries as a function of their resources.

References

12