miracl / MIRACL

MIRACL Cryptographic SDK: Multiprecision Integer and Rational Arithmetic Cryptographic Library is a C software library that is widely regarded by developers as the gold standard open source SDK for elliptic curve cryptography (ECC).
https://miracl.com
654 stars 242 forks source link

Correct bug in BPS encryption algorithm #21

Open johandroz opened 8 years ago

johandroz commented 8 years ago

There is a typo in the algorithm 3 (the encryption algorithm) in [1]. This has the consequence that when the plaintext length is longer than maxb (i.e. when you use the Mode of Operation described in the section 1.2 of [1]) and the plaintext length is a multiple of maxb, FPE_decrypt(FPE_encrypt(X)) != X. You can test this case easily by changing the line 314 of mrfpe.c to n=112. In this case, the radix s is 10 which mean maxb(s) = 56. You can see that the plaintext obtained by decrypting the ciphertext is not equal to the original plaintext.

[1] BPS: a Format-Preserving Encryption Proposal, Eric Brier, Thomas Peyrin and Jacques Stern, http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/proposedmodes/bps/bps-spec.pdf