Re: [STDS-P1619] Does XTS provide protection against watermarking?.
Hi Garry,
For simplicity, let's assume that the XTS "block" size is a multiple of the
block size of the underlying block cipher such that we do not have to deal
with ciphertext stealing.
Then such a watermarking attack would be a chosen plaintext attack on the
indistinguishability of XTS from a perfect tweakable random permutation.
This would contradict the indistinguishability property of XTS under chosen
ciphertext attack proven in section 3.3) of
http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/comments/XTS/XTS_comments-Liskov_Minematsu.pdf
Best regards,
Cyril
Garry Mccracken
<Garry.Mccracken@
WINMAGIC.COM> To
STDS-P1619@xxxxxxxxxxxxxxxxx
07/28/2009 09:42 cc
AM
Subject
[STDS-P1619] Does XTS provide
Please respond to protection against watermarking?.
Garry Mccracken
<Garry.Mccracken@
WINMAGIC.COM>
Hi, does XTS provide protection against watermarking
(http://en.wikipedia.org/wiki/Watermarking_attack )?
http://en.wikipedia.org/wiki/Disk_encryption_theory
mentions watermarking under CBC but doesn't say XTS protects against
watermarking.
Does XTS provide any protection against watermarking?
Garry