Variable-Length Authentication Tag Handling in CCM Mode

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The original CCM mode of operation is vulnerable to attacks when used with variable-length authentication tags and does not provide confidentiality only, limiting its secure use to settings with fixed-length authentication tags, which is a constraint in resource-constrained environments like secured wireless sensor networks.

Innovation Solution

Incorporating a flag indicative of the absence of authentication data and using a protection level encoding to allow variable-length authentication tags, enabling secure transmission without requiring data authenticity, and ensuring confidentiality by including a flag in the data format to indicate the presence or absence of authentication data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If variable-length authentication tags are used in CCM mode, then adaptability to different protection requirements is improved, but security vulnerability increases due to attacks

Engineering Contradiction:
Improveadaptability to different protection requirementsVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by incorporating a flag in the authentication data that indicates the absence of authentication data before the cryptographic processing occurs. This pre-conditioning of the data format allows the system to safely handle variable-length tags by explicitly marking cases where authentication data is not present, thereby preventing security vulnerabilities that would otherwise arise from ambiguous data formats.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If CCM mode provides both confidentiality and authenticity, then security protection is improved, but flexibility to provide confidentiality only is reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidflexibility to provide confidentiality only
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the authentication data field dynamic through the use of a flag that can indicate either the presence or absence of authentication data. This dynamic structure allows the CCM mode to adapt its behavior: when the flag indicates absence of authentication data, the mode provides confidentiality only; when authentication data is present, it provides both confidentiality and authenticity. This resolves the contradiction by making the security services configurable rather than fixed.

Inventive Principle:
Principle #15Dynamics

3Reliability

If fixed-length authentication tags are used, then security reliability is improved, but adaptability to different protection requirements is reduced

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidadaptability to different protection requirements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by introducing a flag parameter that changes the interpretation and processing of authentication data. This flag parameter enables the system to switch between different operational modes: when set to indicate absence of authentication data, it allows variable-length tags with confidentiality-only protection; when authentication data is present, it enables full authentication. This parameter change resolves the contradiction by allowing the system to maintain security reliability through explicit data formatting while simultaneously achieving adaptability to different protection requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8060743B2Cryptographic method and apparatus
Publication Date: 2011.11.15 BLACKBERRY LTD
  • US8060743B2 patent drawing
  • US8060743B2 patent drawing
  • US8060743B2 patent drawing

AI summary

A method of formatting data for transmission to another party including the step of incorporating in the data a flag indicative of the absence of data for authentication of the sender. An authentication tag length is also included to permit variable length tags to be used.