Lecture
Deniable encryption (also called ambiguous encryption) is a cryptographic technique in which two or more different messages are encrypted together under two or more different keys . This method makes it possible to plausibly deny the existence of one message or a group of messages as such. The term "ambiguous encryption" itself was coined by Julian Assange and Ralf Weinmann while working on Rubberhose in 1997–2000.
The concept of deniable encryption aims to provide sufficiently high resistance to coercive attacks. The model of such attacks assumes that the attacker has some means of leverage over the sender, the recipient or the custodian of the encrypted information and forces them to hand over the key for decrypting it. Resistance to coercive attacks is ensured by the fact that at least one of the transmitted messages is not secret, and the attacker is given a key with which decrypting the ciphertext reveals this message. The decryption procedure is carried out in such a way that the attacker has no reasonable grounds to believe that any other messages were associated with the ciphertext. Ambiguous encryption allows the encrypted message to be read in several meaningful ways depending on the key used. In other words, it gives the user a chance to hide a secret message even if they have been forced to disclose one of the keys.
An essential requirement for deniable encryption algorithms is that the bits of the ciphertext influence the bits of the decrypted text with equal probability: changing any bit of the ciphertext must invert any bit of the decrypted text with a probability sufficiently close to 0.5.
Suppose you need to hide a certain amount of critically important data that is of great interest to an adversary. At the same time, simply encrypting a file may not be enough – after all, when faced with an encrypted container, the adversary will want to obtain the password! They may even resort to various kinds of torture, and this method of cryptanalysis produces good results; it is only a matter of time.
In such a case it makes sense to use so-called "ambiguous encryption" or a "false bottom". You create an encrypted container and load arbitrary legitimate data into it (that is, data that a person could quite plausibly keep in an encrypted container, for example private photos), and then, in the free space, you create another area that is opened with a completely different password and into which the truly critical information is written.
When the file comes under the adversary's close scrutiny, our hero declares with a straight face that the file is used to store personal photos. If pressed hard, he gives up his (first) password for the file. The adversary mounts the encrypted container with this password and sees genuinely private photos. In all likelihood, he will leave the container alone and keep searching elsewhere. Well, let's try to implement this!
The essence of a container with a false bottom is extremely simple: when you enter one password, one set of information is shown; when you enter another, a different set is shown. With software and hardware tools it is impossible to prove that a false bottom exists, so if you are required to give access and refusing is impossible, you can give access to the "public" contents, and nobody will learn about the false bottom or what it contains (at the end of this material I will use a real-life example to show that this is a myth).
There is a widespread belief that the hidden area of an encrypted container can be detected by wiping the open part and checking the free space available for writing. If there is a hidden area, it will occupy space, and it will become obvious that the container has a false bottom. In reality this is a myth. The presence of a hidden container has no effect on the main one, even if it takes up the lion's share of its size.
If you write to the container a file that exceeds the size of the container's free area, it will be written over the hidden part, without giving away its presence in any way. Containers with a false bottom are created in the same way in TrueCrypt and VeraCrypt, and in the same way on all operating systems.
A possible scenario looks like this:
Alice can also send one cryptogram to both Bob and Carl. In that case Bob, having decrypted the message with his key, learns that Carl wants to denounce him. To Carl, the letter will say that Bob is trying to steal his money. Alice's attempts to set them against each other will not be exposed until Bob and Carl learn that they have different keys.
Example 1.
Deniable encryption is performed using a secret key in the form of a set of subkeys and two prime numbers
and
.The blocks
and
of the two messages are encrypted by computing the value
by the formula
, computing the value
by the formula
, and forming the ciphertext block C, which is the solution of the system of congruences
which we will write in the form
according to the Chinese remainder theorem, the solution is computed by the following formula:
let the message {\displaystyle {\overline {M}}} be the one intended for disclosure under a coercive attack. Then the attacker is presented, as the encryption key, with the triple of values
. Decryption is performed by the formula
.
In the last formula, the inverse values for the subkeys and
are computed modulo
and {\displaystyle p_{2}}
, respectively. Decryption of the secret message M is performed by the same formula, but using a key consisting of the triple of values
:
Example 2
The encryption key is a set of subkeys and two prime numbers
and
. Two messages
and
are encrypted by generating random numbers
and
, computing the value
by the formula
, computing the value
by the formula
, and forming the ciphertext
, which is the solution of a system of congruences consisting of three congruences
.
This system can be written in the form
According to the Chinese remainder theorem, the solution of this system of congruences is computed by the formula:
Under a coercive attack, the attacker is presented, as the encryption key, with the triple of values , from which decryption is performed by the formula:
.
Obviously, the size of the ciphertext cannot be less than the sum of the sizes of the messages encrypted together, so the signs considered as indicating the presence of other messages in the ciphertext are signs that the ciphertext differs from the ciphertext produced by probabilistic encryption of the disclosed message, in which the ciphertext is significantly larger than the original message. In other words, the ciphertext under attack could have been obtained by probabilistic encryption with the key presented. For this reason, the attacker has no grounds to demand any other key for further decryption of the ciphertext.
The attacker may put forward the following arguments in favor of additional messages being present in the ciphertext:
The size of the ciphertext may be larger than the size of the original text. In this case the attacker is told that the ciphertext was created using a probabilistic encryption method. An increase in ciphertext size is characteristic of ciphers of this type.
This type of encryption is detected when random data or an encryptor bootloader, such as VeraCrypt's, is found. This may be enough to arouse suspicion of the presence of such encryption, with all the ensuing consequences .
Modern methods of ambiguous encryption use the properties of pseudorandom permutations of block ciphers, which makes it impossible to prove that the data is not simply a meaningless set of bits produced by a cryptographically secure pseudorandom sequence generator. This technique is supplemented by revealing to the attacker some decoy data resembling what the user would try to hide. This kind of ambiguous encryption is sometimes called steganographic encryption.
An example is cryptographic file systems that use a scheme of abstract "layers", in which each successive layer requires its own key for decryption. In addition, there are so-called chaff layers, filled with random data to counter the detection of the existence of the real layers as well as of their keys. The user can keep decoy data on several layers, claiming that the remaining space is used as chaff layers. Physically, the data is most often located in a single directory, split into files of equal length with names either chosen at random (in the case of a chaff layer) or representing the output of a cryptographic hash function applied to block identifiers. The timestamps of these files are chosen at random. Examples of such systems are Rubberhose and PhoneBookFS.
Another approach, used by traditional storage-protection packages, consists in creating a new protected volume inside the main one. The process begins with the main container being filled with a disordered set of data during formatting, followed by initialization of the file system. After that, part of the file system is filled with harmless data resembling secret data. Then, somewhere in the remaining space, a new hidden volume is created, used for the data that the user really wants to hide. Since the adversary cannot distinguish encrypted data from the random filler data, he will not be able to detect this hidden volume on the disk. However, the fact that the contents of the non-secret data have not changed since creation, in particular the file modification time — this is done to prevent damage to user data — may arouse suspicion. The solution to this problem is to instruct the system to change the contents of the decoys. Nevertheless, it should be noted that this operation carries the risk of damaging the data stored on the disk. Programs such as FreeOTFE and BestCrypt allow creating several hidden partitions on one disk, whereas TrueCrypt is limited to one.
The existence of a hidden volume can be detected because of flawed implementations that depend on predictable cryptographic values , or with the help of certain forensic tools capable of detecting non-random encrypted data. It has also been suggested that there is a vulnerability to testing of pseudorandom sequences with the chi-squared test (Pearson's test): after each change, the encrypted data must be altered in such a way that its distribution plausibly matches a random distribution.
Deniable encryption is also criticized because it cannot protect users from extortion. The very fact of possessing tools that implement deniable encryption methods may cause an attacker to continue trying to break into the data even after the user has given up a password that provides access to some fake information.
Of course, insufficient cryptographic strength of the block ciphers or of the number generator can compromise the security of such a file system. To avoid doubts about the sufficient cryptographic strength of the generator, one can encrypt pseudorandom data with a key different from that of the main data, which makes the stored information indistinguishable from empty space, since encrypted data cannot be distinguished from other encrypted data. Finally, it should be noted that improper use of encryption modes can make the system vulnerable, for example, to watermarking attacks.[10]
Some cryptographic products (for example, TrueCrypt) allow creating encrypted containers without any signatures. Such a container generally cannot be linked to a specific cryptographic program (since the contents of the container look like one continuous random sequence of data).
Containers without signatures cannot be detected by programs such as file. On the other hand, the absence of any signatures combined with high data entropy is itself a sign of encrypted data.
Some products make it possible to create containers inside an already existing solid random sequence of data. For example, TrueCrypt can create a container inside the free space of the file system of another container (the free space of the file system of any TrueCrypt container is initially filled with random data).
In some cases, hidden containers can be detected at the stage of analyzing a powered-off system, for example:
Some systems that encrypt messages on the fly, for example OTRM, offer flexible encryption, which allows the participants of a conversation to deny their participation in it. Although this type of encryption is not, in essence, deniable in the ambiguous sense, that is, it does not allow a message to be decrypted in two different ways, it deprives the adversary of the ability to prove the participation of a specific person in the conversation, as well as the very fact that any information was exchanged.
This is achieved by adding to the encrypted message the information needed to forge it. Thus, if the adversary is able to create a genuine message for a given conversation, they can automatically forge messages as well, which, together with perfect forward secrecy, guarantees the security of the conversation even if the keys for individual messages are at risk of being disclosed.
These are some of the most difficult situations against which you need to protect yourself and your data. One of the few options is to use secret sharing and to have access to the data only when the keys of two or more people are entered into the system.
For this to work, you will need to announce widely that the information is accessible only when several people enter their passwords, in the same way that banks put signs on their time-delay safes that cannot be opened without waiting, no matter what. If your adversary does not know that this system is in place, they may end up torturing you or putting you in prison because they do not believe you.
Another solution is to set the data to self-destruct when a certain key is entered, using a feature of Kali Linux. If your adversary has captured you, you can simply give them the self-destruct key, and the data from the device will not be recoverable. However, this method works only if the attacker has not been prudent enough to copy the data beforehand, which any technically skilled adversary should do.
If you do this, it will probably all end very badly for you. By destroying the data, you will make your adversary very angry, and brutal torture, long imprisonment or death are not out of the question.
This method is recommended only if you are in a situation where preventing the data from falling into the attacker's hands is more important than your life.
Comments