Classical forgery attacks against Offset Two-round (OTR) structures require some harsh conditions, such as some plaintext and ciphertext pairs need to be known, and the success probability is not too high. To solve these problems, a quantum forgery attack on OTR structure using Simon's algorithm is proposed. The attacker intercept the ciphertext-tag pair $(C,T)$ between the sender and receiver, while Simon's algorithm is used to find the period of the tag generation function in OTR, then we can successfully forge new ciphertext $C'$ ($C'\ne C$) for intercepted tag $T$. For a variant of OTR structure (Pr{/o}st-OTR-Even-Mansour structure), a universal forgery attack, in which it is easy to generate the correct tag of any given message if the attacker is allowed to change a single block in it, is proposed. It first obtains the secret parameter L using Simon's algorithm, then the secret parameter L is used to find the keys $k_1$ and $k_2$, so that an attacker can forge the changed messages. It only needs several plaintext blocks to help obtain the keys to forge any messages. Performance analysis shows that the query complexity of our attack is $O(n)$, and its success probability is very close to 1.
翻译:针对双轮偏移(OTR)结构的经典伪造攻击需要苛刻条件,例如需要已知某些明文密文对,且成功概率不高。为解决上述问题,提出一种利用Simon算法的OTR结构量子伪造攻击。攻击者截获发送方与接收方之间的密文-标签对$(C,T)$,同时利用Simon算法寻找OTR中标签生成函数的周期,从而对截获标签$T$成功伪造新密文$C'$($C'\ne C$)。针对OTR结构变体(Pr{/o}st-OTR-Even-Mansour结构),提出一种通用伪造攻击,即允许攻击者修改消息中单个数据块时,可轻易生成任意给定消息的正确标签。该攻击首先利用Simon算法获取秘密参数$L$,进而使用该秘密参数寻找密钥$k_1$和$k_2$,使攻击者能够伪造被修改后的消息。该攻击仅需若干明文块即可获取密钥以伪造任意消息。性能分析表明,本攻击的查询复杂度为$O(n)$,且成功概率趋近于1。