Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Intel Cascade Cipher

From Wikipedia, the free encyclopedia
Block cipher
Intel Cascaded Cipher
General
DesignersErnie Brickell,
Gary Graunke
Derived fromAES,Serpent
Cipher detail
Key sizes128 bits
Block sizes128 bits
StructureAES-128 in counter mode supplying key material to Serpent
Rounds10 rounds of AES, 3 (out of 32) rounds of Serpent
Best publiccryptanalysis
Specifications not published

Incryptography, theIntel Cascaded Cipher is a high bandwidthblock cipher, used as an optional component of theOutput Content ProtectionDRM scheme of the MicrosoftWindows Vista operating system. The cipher is based onAdvanced Encryption Standard (AES) operating in counter mode, used for generatingkeys, and a 3-round version ofSerpent for encrypting actual content.

The Cascaded Cipher has not been subject to an open peer review process. A license for using the Cascaded Cipher is required fromIntel Corporation.

Description

[edit]

The Cascaded Cipherspecifications are not currently available on the Intel web site or inacademic journals. A description of the structure of the cipher appears in a US patent application. In this case, the patent application only describes the inventive steps as claimed by its inventors, and is not a specification of the cipher as it is intended to be used to protect content in Windows Vista.

There are two embodiments of the cipher described in the US patent application.

CTR-ECB mode

[edit]

In thecounter-electronic codebook mode, the Cascaded Cipher uses full strengthAES-128 in counter mode to generate a securekey stream and supplies this key-stream to a reduced roundSerpent in electronic codebook mode to encrypt eachplaintext block. To increase performance, each inner key stream block is reused several times to encrypt multiple blocks.

CTR-CTR mode

[edit]

In the counter-counter mode, the Cascaded Cipher uses full-strength AES-128 in counter mode to generate a secure key stream and supplies this key-stream to a reduced round Serpent also operating in counter mode to encrypt each plaintext block. To increase performance, each inner key stream block is reused several times to encrypt multiple blocks.

Security

[edit]

In the Microsoft document "Output Content Protection and Windows Vista", it is claimed that: "Thesecurity level achieved for typical video data is estimated to be approaching that of regular AES. This assertion is being tested by Intel putting its Cascaded Cipher out to the cryptography community to get their security assessment — that is, to see if they can break it."

The security of the system requires that it is impossible to recover the currently active inner key from the output of the reduced round Serpent encrypted video stream. Furthermore, the security of this method is highly sensitive to the number of rounds used in Serpent, the mode of operation described in the patent application, and the number of times the inner key is reused.

References

[edit]
Common
algorithms
Less common
algorithms
Other
algorithms
Design
Attack
(cryptanalysis)
Standardization
Utilization
General
Mathematics
Retrieved from "https://en.wikipedia.org/w/index.php?title=Intel_Cascade_Cipher&oldid=1240895042"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp