Cryptography has become an essential part of our everyday life. Cryptanalysis studies the practical security of the encryption schemes we use. The importance of this study has been demonstrated by the fact that numerous widely used schemes were shown to be practically insecure.
This project concerns cryptanalysis of resource constrained (so-called, 'lightweight') encryption schemes, deployed in most Internet-of-Things (IoT) devices. Our motivation is that in order to address the challenge of lightweight cryptography, it is not sufficient to adjust the current designs and analysis to the constrained environment. Instead, we must establish a new research methodology, aiming directly at the problems arising in the 'lightweight realm'.
The project concentrates on four main directions. First, in order to enable conceptually new designs, we go 'a level up' to study the security of the generic schemes serving as building blocks of most ciphers. Second, considering specific ciphers we pursue low complexity cryptanalysis, being more relevant to the lightweight realm than 'standard' attacks. Third, we pursue new directions toward establishing 'white-box cryptography' – a central challenge in cryptography for the IoT. Finally, we explore further applications of discrete analysis to lightweight cryptography, aiming in particular to address the fundamental question of establishing rigorous conditions under which the standard cryptanalytic techniques apply.
For the near future, we hope that our project will enable detecting weaknesses in the lightweight ciphers we use and fixing them before being exploited by the 'bad guys'. Looking forward farther, we hope to understand how to design secure lightweight ciphers for the billions of IoT devices to come.
Conclusions: During the project, we obtained numerous significant results which advanced our understanding of lightweight encryption schemes and also had a practical impact on current design of encryption schemes. Most notably, we found a way to use discrete analysis to show that widely used techniques of cryptanalysis cannot be improved. This achievement is very important as it allows proving rigorously that our encryption schemes are immune to various types of attacks. Futhermore, we significantly advanced the state-of-the-art on the security of the AES, the most widely used cipher worldwide. We achieved this by improving by a large margin the best known practical attacks on reduced round versions of AES, resolving a 20-year old open problem. These results not only improve our understanding of the security of the AES, but also affect numerous lightweight cryptosystems which use reduced-round versions of the AES as a component. In addition, we mounted practical attacks on several other ciphers, which had an immediate practical impact: The ciphers Lilliput-AE and Flex-AEAD, which were candidates for selection by the US NIST as the new lightweight encryption standard were discarded from the competition due to our attacks. Finally, we developed a number of new attack techniques, which have already been adopted by numerous other research groups for assessing the security of new designs. The results we achieved in the project significantly advance the state-of-the-art of research in cryptanalysis, and as we hoped, give us a better understanding of how to design the lightweight ciphers for the billions of IoT devices to come.