New efficient padding methods secure against padding oracle attacks

HyungChul Kang, Myungseo Park, Dukjae Moon, Changhoon Lee, Jongsung Kim, Kimoon Kim, Juhyuk Kim, Seokhie Hong

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

This paper proposes three new padding methods designed to withstand padding oracle attacks, which aim at recovering a plaintext without knowing the secret key by exploiting oracle’s characteristic of checking the padding during decryption. Of the ten existing padding methods, only two (ABYT-PAD and ABIT-PAD) can withstand padding oracle attacks. However, these methods are not efficient since they either use a random number generator or require MAC verification in applications. The three new padding methods proposed in this paper are secure against padding oracle attacks and more efficient compared to the two aforementioned padding methods.

Original languageEnglish
Title of host publicationLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
PublisherSpringer Verlag
Pages329-342
Number of pages14
Volume9558
ISBN (Print)9783319308395
DOIs
Publication statusPublished - 2016
Event18th International Conference on Information Security and Cryptology, ICISC 2015 - Seoul, Korea, Republic of
Duration: 2015 Nov 252015 Nov 27

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9558
ISSN (Print)03029743
ISSN (Electronic)16113349

Other

Other18th International Conference on Information Security and Cryptology, ICISC 2015
CountryKorea, Republic of
CitySeoul
Period15/11/2515/11/27

Fingerprint

Attack
Random number Generator

Keywords

  • CBC mode of operation
  • Padding methods
  • Padding oracle attack

ASJC Scopus subject areas

  • Computer Science(all)
  • Theoretical Computer Science

Cite this

Kang, H., Park, M., Moon, D., Lee, C., Kim, J., Kim, K., ... Hong, S. (2016). New efficient padding methods secure against padding oracle attacks. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 9558, pp. 329-342). (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics); Vol. 9558). Springer Verlag. https://doi.org/10.1007/978-3-319-30840-1_21

New efficient padding methods secure against padding oracle attacks. / Kang, HyungChul; Park, Myungseo; Moon, Dukjae; Lee, Changhoon; Kim, Jongsung; Kim, Kimoon; Kim, Juhyuk; Hong, Seokhie.

Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). Vol. 9558 Springer Verlag, 2016. p. 329-342 (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics); Vol. 9558).

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Kang, H, Park, M, Moon, D, Lee, C, Kim, J, Kim, K, Kim, J & Hong, S 2016, New efficient padding methods secure against padding oracle attacks. in Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). vol. 9558, Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), vol. 9558, Springer Verlag, pp. 329-342, 18th International Conference on Information Security and Cryptology, ICISC 2015, Seoul, Korea, Republic of, 15/11/25. https://doi.org/10.1007/978-3-319-30840-1_21
Kang H, Park M, Moon D, Lee C, Kim J, Kim K et al. New efficient padding methods secure against padding oracle attacks. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). Vol. 9558. Springer Verlag. 2016. p. 329-342. (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)). https://doi.org/10.1007/978-3-319-30840-1_21
Kang, HyungChul ; Park, Myungseo ; Moon, Dukjae ; Lee, Changhoon ; Kim, Jongsung ; Kim, Kimoon ; Kim, Juhyuk ; Hong, Seokhie. / New efficient padding methods secure against padding oracle attacks. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). Vol. 9558 Springer Verlag, 2016. pp. 329-342 (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)).
@inproceedings{2e0299460f1b4fc8a9a1ac0746b101dd,
title = "New efficient padding methods secure against padding oracle attacks",
abstract = "This paper proposes three new padding methods designed to withstand padding oracle attacks, which aim at recovering a plaintext without knowing the secret key by exploiting oracle’s characteristic of checking the padding during decryption. Of the ten existing padding methods, only two (ABYT-PAD and ABIT-PAD) can withstand padding oracle attacks. However, these methods are not efficient since they either use a random number generator or require MAC verification in applications. The three new padding methods proposed in this paper are secure against padding oracle attacks and more efficient compared to the two aforementioned padding methods.",
keywords = "CBC mode of operation, Padding methods, Padding oracle attack",
author = "HyungChul Kang and Myungseo Park and Dukjae Moon and Changhoon Lee and Jongsung Kim and Kimoon Kim and Juhyuk Kim and Seokhie Hong",
year = "2016",
doi = "10.1007/978-3-319-30840-1_21",
language = "English",
isbn = "9783319308395",
volume = "9558",
series = "Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)",
publisher = "Springer Verlag",
pages = "329--342",
booktitle = "Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)",

}

TY - GEN

T1 - New efficient padding methods secure against padding oracle attacks

AU - Kang, HyungChul

AU - Park, Myungseo

AU - Moon, Dukjae

AU - Lee, Changhoon

AU - Kim, Jongsung

AU - Kim, Kimoon

AU - Kim, Juhyuk

AU - Hong, Seokhie

PY - 2016

Y1 - 2016

N2 - This paper proposes three new padding methods designed to withstand padding oracle attacks, which aim at recovering a plaintext without knowing the secret key by exploiting oracle’s characteristic of checking the padding during decryption. Of the ten existing padding methods, only two (ABYT-PAD and ABIT-PAD) can withstand padding oracle attacks. However, these methods are not efficient since they either use a random number generator or require MAC verification in applications. The three new padding methods proposed in this paper are secure against padding oracle attacks and more efficient compared to the two aforementioned padding methods.

AB - This paper proposes three new padding methods designed to withstand padding oracle attacks, which aim at recovering a plaintext without knowing the secret key by exploiting oracle’s characteristic of checking the padding during decryption. Of the ten existing padding methods, only two (ABYT-PAD and ABIT-PAD) can withstand padding oracle attacks. However, these methods are not efficient since they either use a random number generator or require MAC verification in applications. The three new padding methods proposed in this paper are secure against padding oracle attacks and more efficient compared to the two aforementioned padding methods.

KW - CBC mode of operation

KW - Padding methods

KW - Padding oracle attack

UR - http://www.scopus.com/inward/record.url?scp=84961194137&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=84961194137&partnerID=8YFLogxK

U2 - 10.1007/978-3-319-30840-1_21

DO - 10.1007/978-3-319-30840-1_21

M3 - Conference contribution

AN - SCOPUS:84961194137

SN - 9783319308395

VL - 9558

T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)

SP - 329

EP - 342

BT - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)

PB - Springer Verlag

ER -