International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 29 May 2012

Jon Passki, Tom Ritter
ePrint Report ePrint Report
Certain block cipher confidentiality modes are susceptible to an adaptive chosen-ciphertext attack against the underlying format of the plaintext. When the application decrypts altered ciphertext and attempts to process the manipulated plaintext, it may disclose information about intermediate values resulting in an oracle. In this paper we describe how to recognize and exploit such an oracle to decrypt ciphertext and control the decryption to result in arbitrary plaintext. We also discuss ways to mitigate and remedy the issue.

Expand

Additional news items may be found on the IACR news page.