Application of Deterministic Authenticated Encryption for Storage Area Networks and Block-Oriented Storage Devices Protection

Georgii V. Firsov, Alisa M. Koreneva, Sergey S. Minakov

Abstract


The purpose of this research is to develop a cryptographic scheme CSSAN for block-oriented storage devices and storage area networks protection. This scheme provides data confidentiality and unit level integrity. By unit-level integrity we mean integrity of each logical data unit (e.g., disk sector) independently. The proposed scheme is built on top of a deterministic authenticated encryption (DAE) scheme. We use a modified Encrypt-then-MAC (EtM) construction to compose a tweakable encryption scheme and message authentication code scheme into a DAE scheme. We reduce security of the CSSAN scheme to security of its components. Further, we prove security of the modified EtM construction. Based on these security reductions, we formulate requirement for basic cryptographic primitives used in the CSSAN scheme.

Full Text:

PDF

References


Chukry, S., & Sbeyti, H. (2019). Security Enhancement in Storage Area Network. In 2019 7th International Symposium on Digital Forensics and Security (ISDFS) (pp. 1–5). IEEE.

Mahalingam, P., Jayaprakash, N., & Karthikeyan, S. (2009). Enhanced Data Security Framework for Storage Area Networks. In 2009 Second International Conference on Environmental and Computer Science (pp. 105–110). IEEE.

Kim, Y., Maino, F., Narasimha, M., & Tsudik, G. (2002). Secure group services for storage area networks. In First International IEEE Security in Storage Workshop, 2002. Proceedings. (pp. 80–93). IEEE Comput. Soc.

Wang, Y., Kumar, A., & Ha, Y. (2014). FPGA-based high throughput XTS-AES encryption/decryption for storage area network. In 2014 International Conference on Field-Programmable Technology (FPT) (pp. 268–271). IEEE.

Isobe, T., & Minematsu, K. (2020). Plaintext Recovery Attacks Against XTS Beyond Collisions. In Selected Areas in Cryptography – SAC 2019 (pp. 103–123). Springer International Publishing.

Firsov, G., & Koreneva, A. (2022). On One Block Cipher Mode of Operation Used to Protect Data on Block-Oriented Storage Devices. Modern Information Technologies and IT-Education, 18(3), 691–701.

Koreneva, A., & Firsov, G. (2025). O svojstvah bezopasnosti odnogo rezhima raboty blochnyh shifrov, prednaznachennogo dlya zashchity informacii na nositelyah s blochno-orientirovannoj strukturoj [On security properties of one block ciphers mode of operation for information protection on block-oriented storage devices]. In Information security systems and tools (pp. 179–184). Penza state University.

Kim, Y., Maino, F., Narasimha, M., Kyung Hyune Rhee, & Tsudik, G. (2003). Storage area networking – Secure group key management for storage area networks . IEEE Communications Magazine, 41(8), 92–99.

Kim, Y., Perrig, A., & Tsudik, G. (2000). Simple and fault-tolerant key agreement for dynamic collaborative groups. In Proceedings of the 7th ACM Conference on Computer and Communications Security (pp. 235–244). Association for Computing Machinery.

Minakov, S., Karpov, I., Tikhov, S., & Martynov, I. (2025). Variant postroeniya programmnogo resheniya s gibridnoj kriptograficheskoj sistemoj zashchity dannyh, hranyashchihsya na oblachnom nakopitele, i perspektivnymi rezhimami raboty blochnyh shifrov [A variant for constructing a software solution with a hybrid cryptographic system for protecting data stored on a cloud drive with perspective block ciphers modes of operation]. In Information security systems and tools (pp. 179–184). Penza state University.

Firsov, G., & Koreneva, A. (2024). On improved security bounds of one block ciphers mode of operation for protection of block-oriented system storage devices. Journal of Computer Virology and Hacking Techniques, 20(3), 513–523.

Firsov, G., & Koreneva, A. (2025). Correction to: On improved security bounds of one block ciphers mode of operation for protection of block-oriented system storage devices. Journal of Computer Virology and Hacking Techniques, 21(1).

Ahmetzyanova, L., Alekseev, E., Sedov, G., Smyshlyaeva, E., & Smyshlyaev, S. (2019). Practical significance of security bounds for standardized internally re-keyed block cipher modes. Mathematical Aspects of Cryptography, 10(2), 31–46.

GOST 34.12-2018. Information technology. Cryptographic protection of information. Block ciphers. (2018). Russian National Bureau of Standards.

Halevi, S., & Rogaway, P. (2003). A Tweakable Enciphering Mode. Advances in Cryptology - CRYPTO 2003, 482–499.

Sarkar, P. (2009). Efficient Tweakable Enciphering Schemes From (Block-Wise) Universal Hash Functions. IEEE Transactions on Information Theory, 55(10), 4749–4760.

Vorobjev, V.I., Rizhkov, C.R., & Phatkieva, R.R. (2015). Zashchita perimetra oblachnyh vychislenij [Cloud computing perimeter protection]. Programmnye sistemy: teoriya i prilozheniya, 6(1), 61 – 71.

Bekker, M.Ya., Terentjev, A.O., Gatchin, Yu.A., & Karmanovskiy, N.S. (2011). Ispol'zovanie cifrovyh sertifikatov i protokolov SSL/TLS dlya shifrovaniya dannyh pri oblachnyh vychisleniyah [Use of digital certificates and SSL/TLS protocols for data encryption in cloud computing]. Nauchno-tekhnicheskij vestnik informacionnyh tekhnologij, mekhaniki i optiki, 74(4), 125–130.

Gunter, E.S., Narutta, N.N., & Shakhov, V.G. (2013). ``Oblachnye'' vychisleniya i problemy ih bezopasnosti [Cloud computations and their security]. Omskij nauchnyj vestnik, 120(2), 278–282.

Minakov, S. (2020). The Main Cryptographic Mechanisms for Protection of Data, Transmitted to Cloud Services and Storage Area Networks. Cybersecurity issues, 3(37), 66–75.

Chakraborty, D., López, C., & Sarkar, P. (2017). Disk encryption: do we need to preserve length?. Journal of Cryptographic Engineering, 8(1), 49–69.

Rogaway, P., & Shrimpton, T. (2007). Deterministic authenticated-encryption.

Fomichev, V., & Koreneva, A. (2020). Encryption performance and security of certain wide block ciphers. Journal of Computer Virology and Hacking Techniques, 16(3), 197–216.

Rogaway, P., & Zhang, Y. (2018). Simplifying Game-Based Definitions: Indistinguishability up to Correctness and Its Application to Stateful AE. In Advances in Cryptology – CRYPTO 2018 (pp. 3–32). Springer International Publishing.

Hoang, V., Krovetz, T., & Rogaway, P. (2015). Robust Authenticated-Encryption AEZ and the Problem That It Solves. In Advances in Cryptology – EUROCRYPT 2015 (pp. 15–44). Springer Berlin Heidelberg.

Bellare, M., & Namprempre, C. (2008). Authenticated Encryption: Relations among Notions and Analysis of the Generic Composition Paradigm. Journal of Cryptology, 21(4), 469–491.

Smith, P. (2020). An Introduction to Formal Logic. Cambridge University Press.

Ahmetzyanova, L., Alekseev, E., Babueva, A., Nikiforova, L., & Smyshlyaev, S. (2021). IQRA: Incremental Quadratic Re-keying friendly Authentication scheme. Mathematical Aspects of Cryptography, 13(3), 5–35.

Shrimpton, T. (2004). A Characterization of Authenticated-Encryption as a Form of Chosen-Ciphertext Security.

Kiryukhin, V. (2024). On the security aspects of protocol CRISP. Mathematical Aspects of Cryptography, 15(1), 57–81.

Khati, L. (2019). Full Disk Encryption and Beyond. (Doctoral dissertation, Universite Paris PSL).

Namprempre, C., Rogaway, P., & Shrimpton, T. (2014). Reconsidering Generic Composition. In Advances in Cryptology – EUROCRYPT 2014 (pp. 257–274). Springer Berlin Heidelberg.

Iwata, T., & Kurosawa, K. (2003). OMAC: One-Key CBC MAC. In Fast Software Encryption (pp. 129–153). Springer Berlin Heidelberg.

Nandi, M. (2009). Improved security analysis for OMAC as a pseudorandom function. Journal of Mathematical Cryptology, 3(2).

R 1323565.1.022–2018. Information technology. Cryptographic protection of information. Key Derivation Functions. (2018). Russian National Bureau of Standards.

Rogaway, P. (2004). Efficient Instantiations of Tweakable Blockciphers and Refinements to Modes OCB and PMAC. In Advances in Cryptology - ASIACRYPT 2004 (pp. 16–31). Springer Berlin Heidelberg.

Lavrikov, I., & Shishkin, V. (2019). How much data may be safely processed on one key in different modes?. Mathematical Aspects of Cryptography, 10(2), 125–134.

Gunsing, A., Daemen, J., & Mennink, B. (2020). Deck-Based Wide Block Cipher Modes and an Exposition of the Blinded Keyed Hashing Model. IACR Transactions on Symmetric Cryptology, 1–22.

Bogdanov, D., & Nozdrunov, V. (2022). Some properties of the DEC mode of operation of block ciphers. Mathematical Aspects of Cryptography, 13(3), 37–44.

Abdalla, M., & Bellare, M. (2000). Increasing the Lifetime of a Key: A Comparative Analysis of the Security of Re-keying Techniques. In Advances in Cryptology — ASIACRYPT 2000 (pp. 546–559). Springer Berlin Heidelberg.

Sachkov, V. (2004). Introduction to combinatorial methods of discrete mathematics. MCNMO.


Refbacks

  • There are currently no refbacks.


Abava  Кибербезопасность ИТ-КОНГРЕСС ВМК МГУ 2026 СНЭ

ISSN: 2307-8162