Share to: share facebook share twitter share wa share telegram print page

QUAD (cipher)

QUAD
General
DesignersCôme Berbain, Henri Gilbert and Jacques Patarin
First publishedMay 28, 2006 (at Eurocrypt)
Cipher detail
Key sizes80 bits
Structuremultivariate system of quadratic equations

In cryptography, the QUAD cipher is a stream cipher which was designed with provable security arguments in mind.

Description

QUAD relies on the iteration of a randomly chosen multivariate quadratic system S=(Q1, ..., Qm) of m=kn equations in n unknowns over a finite field GF(q). The keystream generation process simply consists in iterating the three following steps in order to produce (k -1) n GF(q) keystream values at each iteration.

  • Compute the kn-tuple of GF(q) values S(x) = (Q1(x),..., Qkn(x)) where x is the current value of the internal state;
  • Output the sequence (Qn+1(x),..., Qkn(x)) of (k-1)n GF(q) keystream values
  • Update the internal state x with the sequence of n GF(q) first generated values (Q1(x),..., Qn(x))

QUAD is a modern stream cipher, i.e. it uses a key and an initialisation value (IV) to produce a keystream sequence. A Key and IV setup is also defined which also rely on multivariate quadratic system.

Security

The security of the keystream generation of QUAD is provably reducible to the conjectured intractability of the MQ problem, namely solving a multivariate system of quadratic equations. The first proof was done over field GF(2) for an old-fashioned stream cipher (where the key is the initial state). It was later extended by Berbain and Gilbert in order to take into account the set-up procedure of a modern cipher (with a setup stage deriving the initial state from the key). The security of the whole cipher as a Pseudo Random Function can be related to the conjectured intractability of the MQ problem. The authors also studied the resistance of the cipher against classical attacks.

The authors recommend to use a version of QUAD with an 80-bit key, 80-bit IV and an internal state of n = 160 bits. It outputs 160 keystream bits (m = 320) at each iteration until 240 bits of keystream have been produced.[1]

At Eurocrypt 2006, speed reports were presented for QUAD instances with 160-bit state and output block over the fields GF(2), GF(16), and GF(256). These speed reports were part of an analysis of "Efficient Implementations of Multivariate Quadratic Systems" which was published by Berbain, Billet, and Gilbert at SAC 2006.[2] This analysis (which also covers several multivariate public-key schemes as well as the QUAD stream cipher) studied in part the impact of changing the size of the field on the performances without considering the security aspect.[2]

Discussion on parameters

The initial security theorem for QUAD is valid for the field GF(2) only, and recommended parameters does not achieve to get a contradiction with the proof of security. The authors of QUAD who gave the security theorem acknowledged that a break of QUAD at their suggested parameters does not contradict the proof-of-security theorems when they proposed the scheme at Eurocrypt 2006. However it seemed that the authors had considered them as sufficient to provide the desired security level of about 280.

Yang, Chen, Bernstein and Chen studied the security of the different parameter sets and found some of them very insecure.[3] Their paper discusses both theoretical and practical aspects of attacking QUAD and of attacking the underlying hard problem. For example, this paper shows how to use XL-Wiedemann to break the GF(256) instance QUAD (256, 20, 20) in approximately 266 Opteron cycles, and to break the underlying hard problem in approximately 245 cycles, which was carried out successfully. However, according to this paper, it would take about 2110 to solve an instance of the QUAD(2,160,160) version recommended by the authors of QUAD using XL-Wiedemann.

The study by Yang et al. highlighted the fact that security theorems often rely on reductions with a looseness factor, and when this is taken into account, none of the parameter sets of the suggested versions are sufficient for the proof of security. An instance that will be provably secure would be QUAD(2,320,320), that is, twice as wide as originally proposed.[3]

A security theorem can also be proved for GF(q), albeit with a larger looseness factor; this and extensions of QUAD for more efficient implementations is proposed by Liu et al.[4]

References

  1. ^ Côme Berbain; Henri Gilbert; Jacques Patarin. QUAD: A Practical Stream Cipher with Provable Security (PDF). Annual International Conference on the Theory and Applications of Cryptographic Techniques - EUROCRYPT 2006.
  2. ^ a b Côme Berbain; Olivier Billet; Henri Gilbert. Efficient Implementations of Multivariate Quadratic Systems (PDF). International Workshop on Selected Areas in Cryptography - SAC 2006. doi:10.1007/978-3-540-74462-7_13. Retrieved 2008-03-18.
  3. ^ a b Bo-Yin Yang; Owen Chia-Hsin Chen; Daniel J. Bernstein; Jiun-Ming Chen (2007-03-03). Analysis of QUAD (PDF). Fast software encryption: 14th international workshop, FSE 2007. Retrieved 2008-02-05.
  4. ^ Michael Feng-Hao Liu; Chi-Jen Lu; Bo-Yin Yang; Jintai Ding (October 23, 2007). Secure PRNGs from Specialized Polynomial Maps over Any Fq (PDF). International Workshop on Post-Quantum Cryptography - PQCrypto 2008.

Read other articles:

Half-Life 2Berkas:421px-HL2box.jpg Satu dari tiga sampul Half-Life 2, menampilkan protagonis Gordon Freeman.Publikasi November 16, 2004 Microsoft Windows EU / NA: November 16, 2004[1] Steam November 16, 2004 Xbox Xbox 360 PlayStation 3 Versi Source 24 (Build 5345) GenreFPSKarakterGordon Freeman Latar tempatHalf-Life / Portal universe (en) Bahasa Daftar Belanda, Denmark, Finlandia, Inggris, Italia, Jepang, Jerman, Korea, Norwegia, Polandia, Portugis, Prancis, Rusia, Spanyol, Swedia, Thai,…

Hormon perangsang folikel. Hormon perangsang folikel (Inggris: follitropin, follicle stimulating hormone, FSHcode: en is deprecated ) adalah hormon yang dikeluarkan oleh gonadotropin. FSH berfungsi untuk memacu pertumbuhan dan kematangan folikel atau sel telur dalam ovarium dan juga berpengaruh pada peningkatan hormon estrogen pada wanita. Pada pria, FSH mengatur dan memelihara proses pembentukan sperma. Jumlah FSH sedikit ketika kecil dan tinggi setelah menopause. Pranala luar Day 3 FSH levels …

American state election Not to be confused with 2020 United States House of Representatives elections in Michigan. 2020 Michigan House of Representatives election ← 2018 November 3, 2020 (2020-11-03) 2022 → All 110 seats in the Michigan House of Representatives56 seats needed for a majorityTurnout66.36% 11.72 pp   Majority party Minority party   Leader Lee Chatfield (term-limited) Christine Greig (term-limited) Party Republican Democratic Leader…

General Assembly elections of the U.S. state of New Jersey This article relies largely or entirely on a single source. Relevant discussion may be found on the talk page. Please help improve this article by introducing citations to additional sources.Find sources: 1985 New Jersey General Assembly election – news · newspapers · books · scholar · JSTOR (July 2021) 1985 New Jersey General Assembly election ← 1983 November 5, 1985 1987 → …

Indian cricket manager Bimal Soni Bimal Soni was the manager of the Indian cricket team.[1] He was also President of the Jaipur District Cricket Association, a constituent group of the Rajasthan Cricket Association.[2] References ^ No action against Harbhajan over crowd complaints. ESPNcricinfo. Retrieved 25 January 2010. ^ Power struggle again in Rajasthan. ESPNcricinfo. Retrieved 25 January 2010. This biographical article related to Indian cricket is a stub. You can help Wikipe…

Clade including all birds and their ancestors AvialansTemporal range: Middle Jurassic–Present, 150.8–0 Ma[1] PreꞒ Ꞓ O S D C P T J K Pg N Earliest 165 Ma if Anchiornithidae are members[2] Fossil specimen of Jeholornis prima Collage of four extant birds. Clockwise from top-left: Spanish imperial eagle (Aquila adalberti), common ostrich (Struthio camelus), mallard (Anas platyrhynchos), and common kingfisher (Alcedo atthis) Scientific classification Domain: Eukaryota Kin…

Korean family name (최) This article is about the Korean surname Choi. For Cantonese romanisation of the Chinese surname Cai (蔡), see Cai (surname). ChoiPronunciation[tɕʰwe] or [tɕʰø]Language(s)KoreanOriginMeaningBest, Top, Most, PinnacleRegion of originKoreaOther namesAlternative spellingCh'oe, Tsoi, Chye, Chwe, CheyVariant form(s)Cui, Thôi ChoiHangul최Hanja崔Revised RomanizationChoeMcCune–ReischauerCh'oe 54% of Korean people bear the family name Kim, Lee, Park, Cho…

Синелобый амазон Научная классификация Домен:ЭукариотыЦарство:ЖивотныеПодцарство:ЭуметазоиБез ранга:Двусторонне-симметричныеБез ранга:ВторичноротыеТип:ХордовыеПодтип:ПозвоночныеИнфратип:ЧелюстноротыеНадкласс:ЧетвероногиеКлада:АмниотыКлада:ЗавропсидыКласс:Птиц…

Stadium built for the 1976 Olympic Games in Montreal Olympic StadiumThe Big OOlympic StadiumLocation in MontrealShow map of MontrealOlympic StadiumLocation in QuebecShow map of QuebecOlympic StadiumLocation in CanadaShow map of CanadaAddress4545 Pierre-de-Coubertin AvenueLocationMontreal, Quebec, CanadaCoordinates45°33′29″N 73°33′07″W / 45.558°N 73.552°W / 45.558; -73.552Public transit Pie-IX, ViauOwnerRégie des Installations Olympiques (Government of Quebec)…

Place in Gauteng, South Africa Place in Gauteng, South AfricaSpringsDowntown Springs SkylineSpringsShow map of GautengSpringsShow map of South AfricaCoordinates: 26°15′17″S 28°26′34″E / 26.25472°S 28.44278°E / -26.25472; 28.44278CountrySouth AfricaProvinceGautengMunicipalityEkurhuleniEstablished1904Area[1] • Total183.50 km2 (70.85 sq mi)Elevation1,627 m (5,338 ft)Population (2011)[1] • Total…

Reale Marina dell'Oman البحرية السلطانية العمانيةL'emblema della marina omanita Descrizione generaleNazione Oman Dimensione4.200 uomini Guarnigione/QGAs Sib Fonti nel testo Voci su marine militari presenti su Wikipedia La Al-Bahriyya al-Malikiyya al-‘Umāniyya, Reale Marina dell'Oman nota internazionalmente come Royal Navy of Oman (arabo: البحرية السلطانية العمانية), abbreviato RNO, è la forza navale delle forze armate del Sultanato di Oman…

Public high school in Allentown, Pennsylvania, United StatesParkland High SchoolParkland High School in March 2020Address2700 North Cedar Crest BoulevardAllentown, Pennsylvania 18104United StatesCoordinates40°38′20″N 75°32′47″W / 40.6388°N 75.5465°W / 40.6388; -75.5465InformationTypePublic high schoolEstablished1949School districtParkland School DistrictSuperintendentMark MadsonNCES School ID421851002829[1]PrincipalNathan DavidsonTeaching staff216.9 (o…

Gian Piero Gasperini Informasi pribadiTanggal lahir 26 Januari 1958 (umur 66)Tempat lahir Grugliasco, ItaliaPosisi bermain GelandangInformasi klubKlub saat ini Atalanta (manajer)Karier junior1967–1976 JuventusKarier senior*Tahun Tim Tampil (Gol)1976–1977 Juventus 0 (0)1977–1978 → Reggiana (loan) 16 (0)1978–1983 Palermo 128 (11)1983–1984 S.S. Cavese 1919 34 (2)1984–1985 A.C. Pistoiese 34 (4)1985–1990 Pescara 160 (21)1990–1991 Salernitana 35 (1)1991–1993 Vis Pesaro 61 (3)K…

Voice and video conferencing software Parts of this article (those related to Lede, § History) need to be updated. The reason given is: currently developed? Ekiga 5 was never released.. Please help update this article to reflect recent events or newly available information. (August 2023) EkigaEkiga 3.0.0Developer(s)Damien SandrasStable release4.0.1[1]  / 21 February 2013Preview releasen/a (n/a) [±] Repositorygitlab.gnome.org/Archive/ekiga Written inC/C++, with GUI writ…

艾德礼伯爵 阁下The Rt Hon. The Earl AttleeKG OM CH PC FRS联合王国首相任期1945年7月26日—1951年10月26日君主乔治六世副职赫伯特·莫里森前任温斯顿·丘吉尔继任温斯顿·丘吉尔联合王国副首相任期1942年2月19日—1945年5月23日(战时内阁)君主乔治六世首相温斯顿·丘吉尔前任职位创立继任赫伯特·莫里森反对党领袖任期1951年10月26日—1955年11月25日君主乔治六世伊丽莎白二世…

Voce principale: Coppa del mondo per club FIFA 2010. Finale della Coppa del mondo per club FIFA 2010Lo Stadio Sheikh Zayed di Abu Dhabi, teatro della finale.Informazioni generaliSport Calcio CompetizioneCoppa del mondo per club FIFA 2010 Data18 dicembre 2010 CittàAbu Dhabi ImpiantoStadio Sheikh Zayed Spettatori42 174 Dettagli dell'incontro  TP Mazembe  Inter 0 3 Arbitro Yūichi Nishimura MVP Samuel Eto'o Successione ← Finale della Coppa del mondo per club FIFA 2009 Fin…

Джордж Гаскойн Дата рождения 1525[1] Место рождения Кардингтон[d], Бедфорд, Бедфордшир, Англия Дата смерти 7 октября 1577(1577-10-07)[2] или 1577[3] Место смерти Барнак[d], Питерборо[d], Кембриджшир, Англия Страна  Королевство Англия Род деятельности поэт, …

Rawa Bento Rawa Bento merupakan rawa tertinggi yang ada di Sumatra yaitu pada ketinggian 1333 mdpl.[1] Rawa ini terletak di terletak di Desa Jernih Jaya, Kecamatan Gunung Tujuh, Kabupaten Kerinci, Jambi. Kawasan rawa dengan luas kurang lebih 1000 ha ini memiliki ekosistem rawa yang terdiri atas rumput rawa gambut, hutan rawa kerdil, serta danau rawa kecil. Rawa Bento berasal dari kata Bento, dalam bahasa lokal berarti rumput. Rumput rawa gambut pada rawa Bento didominasi oleh rumput Bent…

American explorer, scientist, philanthropist John Innes KaneBorn(1850-07-29)July 29, 1850DiedFebruary 1, 1913(1913-02-01) (aged 62)Manhattan, New York, U.S.Resting placeGreen-Wood CemeterySpouse Annie Cottenet Schermerhorn ​ ​(m. 1878)​RelativesWoodbury Kane (brother)S. Nicholson Kane (brother)Sybil Kent Kane (sister)DeLancey Astor Kane (brother) John Innes Kane (July 29, 1850 – February 1, 1913)[1] was an American explorer, scientist and philant…

Finnish women's organization Group of suffragists in Helsinki, c.1900 Naisasialiitto Unioni (Finnish) or Kvinnosaksförbundet Unionen (Swedish), sometimes referred to in English as the League of Finnish Feminists,[1] is a non-profit Finnish women's organization which was established in 1892. Since 1904 it has been the Finnish arm of the International Alliance of Women. The co-founders were Lucina Hagman, Maikki Friberg and Venny Soldan-Brofeldt. Unioni was initially concerned with women'…

Kembali kehalaman sebelumnya