Deniable Encryption

Lecture



Deniable encryption (also called ambiguous encryption) is a cryptographic technique in which two or more different messages are encrypted together under two or more different keys . This method makes it possible to plausibly deny the existence of one message or a group of messages as such. The term "ambiguous encryption" itself was coined by Julian Assange and Ralf Weinmann while working on Rubberhose in 1997–2000.

Purpose

The concept of deniable encryption aims to provide sufficiently high resistance to coercive attacks. The model of such attacks assumes that the attacker has some means of leverage over the sender, the recipient or the custodian of the encrypted information and forces them to hand over the key for decrypting it. Resistance to coercive attacks is ensured by the fact that at least one of the transmitted messages is not secret, and the attacker is given a key with which decrypting the ciphertext reveals this message. The decryption procedure is carried out in such a way that the attacker has no reasonable grounds to believe that any other messages were associated with the ciphertext. Ambiguous encryption allows the encrypted message to be read in several meaningful ways depending on the key used. In other words, it gives the user a chance to hide a secret message even if they have been forced to disclose one of the keys.

An essential requirement for deniable encryption algorithms is that the bits of the ciphertext influence the bits of the decrypted text with equal probability: changing any bit of the ciphertext must invert any bit of the decrypted text with a probability sufficiently close to 0.5.

Suppose you need to hide a certain amount of critically important data that is of great interest to an adversary. At the same time, simply encrypting a file may not be enough – after all, when faced with an encrypted container, the adversary will want to obtain the password! They may even resort to various kinds of torture, and this method of cryptanalysis produces good results; it is only a matter of time.

In such a case it makes sense to use so-called "ambiguous encryption" or a "false bottom". You create an encrypted container and load arbitrary legitimate data into it (that is, data that a person could quite plausibly keep in an encrypted container, for example private photos), and then, in the free space, you create another area that is opened with a completely different password and into which the truly critical information is written.

When the file comes under the adversary's close scrutiny, our hero declares with a straight face that the file is used to store personal photos. If pressed hard, he gives up his (first) password for the file. The adversary mounts the encrypted container with this password and sees genuinely private photos. In all likelihood, he will leave the container alone and keep searching elsewhere. Well, let's try to implement this!

The essence of a container with a false bottom is extremely simple: when you enter one password, one set of information is shown; when you enter another, a different set is shown. With software and hardware tools it is impossible to prove that a false bottom exists, so if you are required to give access and refusing is impossible, you can give access to the "public" contents, and nobody will learn about the false bottom or what it contains (at the end of this material I will use a real-life example to show that this is a myth).

There is a widespread belief that the hidden area of an encrypted container can be detected by wiping the open part and checking the free space available for writing. If there is a hidden area, it will occupy space, and it will become obvious that the container has a false bottom. In reality this is a myth. The presence of a hidden container has no effect on the main one, even if it takes up the lion's share of its size.

If you write to the container a file that exceeds the size of the container's free area, it will be written over the hidden part, without giving away its presence in any way. Containers with a false bottom are created in the same way in TrueCrypt and VeraCrypt, and in the same way on all operating systems.

Scenario

A possible scenario looks like this:

  1. Alice is the wife of Bob, who suspects her of infidelity. She wants to send a message to her secret lover Carl. She constructs 2 keys: one to keep secret, and a second that can be sacrificed in a critical situation. She then gives the real key (and perhaps both) to Carl.
  2. After that she writes Carl a harmless message M1 about the life habits of snails — this message can be shown to Bob if he discovers their correspondence — as well as a letter M2 to Carl full of passionate feelings. She then combines these two messages and sends the resulting ciphertext to Carl.
  3. Carl, using the keys given to him, decrypts the original message M2 and, if he wishes, M1.
  4. Bob discovers the message sent by Alice to Carl. In a fit of jealousy he forces Alice to decrypt the letter.
  5. Alice recovers the plaintext M1 using the sacrificial key. Thus Bob gets a boring text about snails, and since the existence of another key is kept secret, he concludes that the message carried no suspicious meaning.

Alice can also send one cryptogram to both Bob and Carl. In that case Bob, having decrypted the message with his key, learns that Carl wants to denounce him. To Carl, the letter will say that Bob is trying to steal his money. Alice's attempts to set them against each other will not be exposed until Bob and Carl learn that they have different keys.

Implementation

Implementation algorithms

Example 1.

Deniable encryption is performed using a secret key in the form of a set of subkeys Deniable Encryption and two prime numbers Deniable Encryption and Deniable Encryption.The blocks Deniable Encryption and Deniable Encryption of the two messages are encrypted by computing the value Deniable Encryption by the formula Deniable Encryption, computing the value Deniable Encryption by the formula Deniable Encryption, and forming the ciphertext block C, which is the solution of the system of congruences


Deniable Encryption

which we will write in the form


Deniable Encryption

according to the Chinese remainder theorem, the solution is computed by the following formula:

Deniable Encryption

let the message {\displaystyle {\overline {M}}}Deniable Encryption be the one intended for disclosure under a coercive attack. Then the attacker is presented, as the encryption key, with the triple of values Deniable Encryption. Decryption is performed by the formula

Deniable Encryption.

In the last formula, the inverse values for the subkeys Deniable Encryption and Deniable Encryption are computed modulo Deniable Encryption and {\displaystyle p_{2}}Deniable Encryption, respectively. Decryption of the secret message M is performed by the same formula, but using a key consisting of the triple of values Deniable Encryption:

Deniable Encryption

Example 2

The encryption key is a set of subkeys Deniable Encryption and two prime numbers Deniable Encryption and Deniable Encryption. Two messages Deniable Encryption and Deniable Encryption are encrypted by generating random numbers Deniable Encryption and Deniable Encryption, computing the value Deniable Encryption by the formula Deniable Encryption, computing the value Deniable Encryption by the formula Deniable Encryption, and forming the ciphertext Deniable Encryption, which is the solution of a system of congruences consisting of three congruences

Deniable Encryption.

This system can be written in the form

Deniable Encryption
According to the Chinese remainder theorem, the solution of this system of congruences is computed by the formula:

Deniable Encryption

Under a coercive attack, the attacker is presented, as the encryption key, with the triple of values Deniable Encryption, from which decryption is performed by the formula:

Deniable Encryption.

Detection

Obviously, the size of the ciphertext cannot be less than the sum of the sizes of the messages encrypted together, so the signs considered as indicating the presence of other messages in the ciphertext are signs that the ciphertext differs from the ciphertext produced by probabilistic encryption of the disclosed message, in which the ciphertext is significantly larger than the original message. In other words, the ciphertext under attack could have been obtained by probabilistic encryption with the key presented. For this reason, the attacker has no grounds to demand any other key for further decryption of the ciphertext.

The attacker may put forward the following arguments in favor of additional messages being present in the ciphertext:

  • Incomplete use of the ciphertext during decryption;
  • Key-controlled branching in the decryption procedure;
  • Signs of sorting of the ciphertext bits in the decryption procedure;
  • Violation of the uniformity of the decryption process across all possible values of the secret key;
  • Non-uniform influence of the ciphertext bits on the bits of the decrypted text.

The size of the ciphertext may be larger than the size of the original text. In this case the attacker is told that the ciphertext was created using a probabilistic encryption method. An increase in ciphertext size is characteristic of ciphers of this type.

This type of encryption is detected when random data or an encryptor bootloader, such as VeraCrypt's, is found. This may be enough to arouse suspicion of the presence of such encryption, with all the ensuing consequences .

Modern Methods of Ambiguous Encryption

Modern methods of ambiguous encryption use the properties of pseudorandom permutations of block ciphers, which makes it impossible to prove that the data is not simply a meaningless set of bits produced by a cryptographically secure pseudorandom sequence generator. This technique is supplemented by revealing to the attacker some decoy data resembling what the user would try to hide. This kind of ambiguous encryption is sometimes called steganographic encryption.

An example is cryptographic file systems that use a scheme of abstract "layers", in which each successive layer requires its own key for decryption. In addition, there are so-called chaff layers, filled with random data to counter the detection of the existence of the real layers as well as of their keys. The user can keep decoy data on several layers, claiming that the remaining space is used as chaff layers. Physically, the data is most often located in a single directory, split into files of equal length with names either chosen at random (in the case of a chaff layer) or representing the output of a cryptographic hash function applied to block identifiers. The timestamps of these files are chosen at random. Examples of such systems are Rubberhose and PhoneBookFS.

Another approach, used by traditional storage-protection packages, consists in creating a new protected volume inside the main one. The process begins with the main container being filled with a disordered set of data during formatting, followed by initialization of the file system. After that, part of the file system is filled with harmless data resembling secret data. Then, somewhere in the remaining space, a new hidden volume is created, used for the data that the user really wants to hide. Since the adversary cannot distinguish encrypted data from the random filler data, he will not be able to detect this hidden volume on the disk. However, the fact that the contents of the non-secret data have not changed since creation, in particular the file modification time — this is done to prevent damage to user data — may arouse suspicion. The solution to this problem is to instruct the system to change the contents of the decoys. Nevertheless, it should be noted that this operation carries the risk of damaging the data stored on the disk. Programs such as FreeOTFE and BestCrypt allow creating several hidden partitions on one disk, whereas TrueCrypt is limited to one.

The existence of a hidden volume can be detected because of flawed implementations that depend on predictable cryptographic values , or with the help of certain forensic tools capable of detecting non-random encrypted data. It has also been suggested that there is a vulnerability to testing of pseudorandom sequences with the chi-squared test (Pearson's test): after each change, the encrypted data must be altered in such a way that its distribution plausibly matches a random distribution.

Deniable encryption is also criticized because it cannot protect users from extortion. The very fact of possessing tools that implement deniable encryption methods may cause an attacker to continue trying to break into the data even after the user has given up a password that provides access to some fake information.

Of course, insufficient cryptographic strength of the block ciphers or of the number generator can compromise the security of such a file system. To avoid doubts about the sufficient cryptographic strength of the generator, one can encrypt pseudorandom data with a key different from that of the main data, which makes the stored information indistinguishable from empty space, since encrypted data cannot be distinguished from other encrypted data. Finally, it should be noted that improper use of encryption modes can make the system vulnerable, for example, to watermarking attacks.[10]

Containers without signatures

Some cryptographic products (for example, TrueCrypt) allow creating encrypted containers without any signatures. Such a container generally cannot be linked to a specific cryptographic program (since the contents of the container look like one continuous random sequence of data).

Containers without signatures cannot be detected by programs such as file. On the other hand, the absence of any signatures combined with high data entropy is itself a sign of encrypted data.

Hidden containers

Some products make it possible to create containers inside an already existing solid random sequence of data. For example, TrueCrypt can create a container inside the free space of the file system of another container (the free space of the file system of any TrueCrypt container is initially filled with random data).

In some cases, hidden containers can be detected at the stage of analyzing a powered-off system, for example:

  • If information about the contents of the hidden container leaks onto unencrypted file systems:
    • Leaks into the swap file, the hibernation file and memory dumps (crash dumps);
    • Other leaks (for example, into MRU lists);
  • If cryptographic keys or passwords leak into the swap file, the hibernation file or memory dumps;
  • If a full or partial copy (or several copies) of the outer container exists together with its key / password;
  • If weak keys / passwords are used for the hidden container.

Flexible encryption

Some systems that encrypt messages on the fly, for example OTRM, offer flexible encryption, which allows the participants of a conversation to deny their participation in it. Although this type of encryption is not, in essence, deniable in the ambiguous sense, that is, it does not allow a message to be decrypted in two different ways, it deprives the adversary of the ability to prove the participation of a specific person in the conversation, as well as the very fact that any information was exchanged.

This is achieved by adding to the encrypted message the information needed to forge it. Thus, if the adversary is able to create a genuine message for a given conversation, they can automatically forge messages as well, which, together with perfect forward secrecy, guarantees the security of the conversation even if the keys for individual messages are at risk of being disclosed.

Alternatives to deniable encryption

These are some of the most difficult situations against which you need to protect yourself and your data. One of the few options is to use secret sharing and to have access to the data only when the keys of two or more people are entered into the system.

For this to work, you will need to announce widely that the information is accessible only when several people enter their passwords, in the same way that banks put signs on their time-delay safes that cannot be opened without waiting, no matter what. If your adversary does not know that this system is in place, they may end up torturing you or putting you in prison because they do not believe you.

Another solution is to set the data to self-destruct when a certain key is entered, using a feature of Kali Linux. If your adversary has captured you, you can simply give them the self-destruct key, and the data from the device will not be recoverable. However, this method works only if the attacker has not been prudent enough to copy the data beforehand, which any technically skilled adversary should do.

If you do this, it will probably all end very badly for you. By destroying the data, you will make your adversary very angry, and brutal torture, long imprisonment or death are not out of the question.

This method is recommended only if you are in a situation where preventing the data from falling into the attacker's hands is more important than your life.

Software for deniable encryption

  • OpenPuff, free encryption software for Windows.
  • BestCrypt, a commercial on-the-fly disk encryption application for Windows.
  • FreeOTFE, free on-the-fly disk encryption software for Windows and Pocket PC, providing deniable encryption functionality along with plausible deniability[11]. It is feature-rich and requires no installation.
  • Off-the-Record Messaging, a cryptographic protocol for instant messaging networks with deniability
  • StegFS, a cryptographic file system for Linux with deniability, the successor of the now unsupported projects PhoneBookFS and rubberhose
  • TrueCrypt, an application for Windows, MAC OS and Linux with on-the-fly disk encryption, capable of deniable encryption to a limited degree[12] and with deniability[13] (given the limited number of hidden volumes per volume). It also requires no installation.
  • Vanish, a prototype of self-destructing data storage.
  • ScramDisk 4 Linux, a free software package for GNU/Linux able to work with TrueCrypt and ScramDisk containers.

See also

  • Rubber-hose cryptanalysis
  • Steganography
  • Chinese remainder theorem
  • Honey encryption
  • Steganography

Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "Information security, Malicious, and information security"

Terms: Information security, Malicious, and information security