SearcharxivSearch

arXiv subjects

Chris J Mitchell

Publications and source records attributed to Chris J Mitchell.

At least 19 recordsLinked to original sources

Weight-constrained cut-down de Bruijn sequences

In 2011/12, Ruskey, Sawada, Stevens and Williams showed that a binary cut-down de Bruijn sequence can be constructed containing all $n$-tuples of Hamming weight either $r$ or $r+1$ for every possible $r$, and no others. In this paper we examine extensions of this result that require choosing a weight-like function applying to $n$-tuples with symbols taken from an alphabet of arbitrary (finite) size. We consider three possible such weight functions, and in each case establish an analogous result to that of Ruskey et al.

math.CO

Negative Avoiding Sequences

Negative avoiding sequences of span $n$ are periodic sequences of elements from $\mathbb{Z}_k$ for some $k$ with the property that no $n$-tuple occurs more than once in a period and if an $n$-tuple does occur then its negative does not. They are a special type of cut-down de Bruijn sequence with potential position-location applications. We establish a simple upper bound on the period of such a sequence, and refer to sequences meeting this bound as maximal negative avoiding sequences. We then go on to demonstrate the existence of maximal negative avoiding sequences for every $k\geq3$ and every $n\geq2$.

math.CO

Constructing orientable and negative orientable sequences with asymptotically optimal period

Orientable sequences, periodic sequences in which any $n$-tuple appears at most once in either direction, were introduced in the early 1990s for use in certain position location applications; constructions and upper bounds on the period for the binary case were published by Dai et al. More recent work has focussed on $k$-ary sequences for arbitrary $k>2$; one method of construction involves negative orientable sequences, in which an $n$-tuple appears at most once in either the sequence or the negative of its reverse. In this paper we show how additional $n$-tuples can be added to one previously described approach for generating negative orientable sequences, resulting in new sequences with asymptotically optimal period. These sequences can in turn be used to generate orientable sequences, again with asymptotically optimal period.

math.CO

New upper bounds for the period of a negative orientable sequence

Negative orientable sequences, i.e. periodic sequences with elements from a finite alphabet of size at least three in which an n-tuple or the negative of its reverse appears at most once in a period of the sequence, were introduced by Alhakim et al. in 2024. The main goal in defining them was as a means of generating orientable sequences, which have automatic position location applications, although they are potentially of interest in their own right. In this paper we develop new upper bounds on the period of negative orientable sequences which, for n>2, are significantly sharper than the previous known bound. The approach used to develop the new bounds involves examining the nodes in the subgraph of the de Bruijn graph corresponding to a negative orientable sequence, and to consider the implications of the fact that the in-degree of every vertex in this subgraph must equal the out-degree. However, despite improving the bounds, a gap remains between the largest known period for a negative orientable sequence and the corresponding bounds for every n>2.

math.CO

New orientable sequences

Orientable sequences of order n are infinite periodic sequences with symbols drawn from a finite alphabet of size k with the property that any particular subsequence of length n occurs at most once in a period in either direction. They were introduced in the early 1990s in the context of possible applications in position sensing. Bounds on the period of such sequences and a range of methods of construction have been devised, although apart from very small cases a significant gap remains between the largest known period for such a sequence and the best known upper bound. In this paper we first give improved upper bounds on the period of such sequences. We then give a new general method of construction for orientable sequences involving subgraphs of the de Bruijn graph with special properties, and describe two different approaches for generating such subgraphs. This enables us to construct orientable sequences with periods meeting the improved upper bounds when n is 2 or 3, as well as n=4 and k odd. For 4\leq n\leq 8, in some cases the sequences produced by the methods described have periods larger than for any previously known sequences.

math.CO

Special orientable sequences

Analogously to de Bruijn sequences, Orientable sequences have application in automatic position-location applications and, until recently, studies of these sequences focused on the binary case. In recent work by Alhakim et al., recursive methods of construction were described for orientable sequences over arbitrary finite alphabets, requiring 'starter sequences' with special properties. Some of these methods required as input special orientable sequences, i.e. orientable sequences which were simultaneously negative orientable. We exhibit methods for constructing special orientable sequences with properties appropriate for use in two of the recursive methods of Alhakim et al. As a result we are able to show how to construct special orientable sequences for arbitrary sizes of alphabet (larger than a small lower bound) and for all window sizes. These sequences have periods asymptotic to the optimal as the alphabet size increases.

math.CO

Orientable and negative orientable sequences

Analogously to de Bruijn sequences, orientable sequences have application in automatic position-location applications and, until recently, studies of these sequences focused on the binary case. In recent work by Alhakim et al., a range of methods of construction were described for orientable sequences over arbitrary finite alphabets; some of these methods involve using negative orientable sequences as a building block. In this paper we describe three techniques for generating such negative orientable sequences, as well as upper bounds on their period. We then go on to show how these negative orientable sequences can be used to generate orientable sequences with period close to the maximum possible for every non-binary alphabet size and for every tuple length. In doing so we use two closely related approaches described by Alhakim et al.

math.CO

Integrity-protecting block cipher modes -- Untangling a tangled web

This paper re-examines the security of three related block cipher modes of operation designed to provide authenticated encryption. These modes, known as PES-PCBC, IOBC and EPBC, were all proposed in the mid-1990s. However, analyses of security of the latter two modes were published more recently. In each case one or more papers describing security issues with the schemes were eventually published, although a flaw in one of these analyses (of EPBC) was subsequently discovered - this means that until now EPBC had no known major issues. This paper establishes that, despite this, all three schemes possess defects which should prevent their use - especially as there are a number of efficient alternative schemes possessing proofs of security.

cs.CR

Constructing orientable sequences

This paper describes new, simple, recursive methods of construction for orientable sequences, i.e. periodic binary sequences in which any n-tuple occurs at most once in a period in either direction. As has been previously described, such sequences have potential applications in automatic position-location systems, where the sequence is encoded onto a surface and a reader needs only examine n consecutive encoded bits to determine its location and orientation on the surface. The only previously described method of construction (due to Dai et al.) is somewhat complex, whereas the new techniques are simple to both describe and implement. The methods of construction cover both the standard `infinite periodic' case, and also the aperiodic, finite sequence, case. Both the new methods build on the Lempel homomorphism, first introduced as a means of recursively generating de Bruijn sequences.

math.CO

Provably insecure group authentication: Not all security proofs are what they claim to be

A paper presented at the ICICS 2019 conference describes what is claimed to be a `provably secure group authentication [protocol] in the asynchronous communication model'. We show here that this is far from being the case, as the protocol is subject to serious attacks. To try to explain this troubling case, an earlier (2013) scheme on which the ICICS 2019 protocol is based was also examined and found to possess even more severe flaws - this latter scheme was previously known to be subject to attack, but not in quite as fundamental a way as is shown here. Examination of the security theorems provided in both the 2013 and 2019 papers reveals that in neither case are they exactly what they seem to be at first sight; the issues raised by this are also briefly discussed.

cs.CR

The (in)security of some recently proposed lightweight key distribution schemes

Two recently published papers propose some very simple key distribution schemes designed to enable two or more parties to establish a shared secret key with the aid of a third party. Unfortunately, as we show, most of the schemes are inherently insecure and all are incompletely specified - moreover, claims that the schemes are inherently lightweight are shown to be highly misleading. We also briefly critique a somewhat related very recent paper by the same authors that uses similar techniques to achieve what are claimed to be secure multiparty computations.

cs.CR

How not to secure wireless sensor networks revisited: Even if you say it twice it's still not secure

Two recent papers describe almost exactly the same group key establishment protocol for wireless sensor networks. Quite part from the duplication issue, we show that both protocols are insecure and should not be used - a member of a group can successfully impersonate the key generation centre and persuade any other group member to accept the wrong key value. This breaks the stated objectives of the schemes.

cs.CR

Who Needs Trust for 5G?

There has been much recent discussion of the criticality of the 5G infrastructure, and whether certain vendors should be able to supply 5G equipment. The key issue appears to be about trust, namely to what degree the security and reliability properties of 5G equipment and systems need to be trusted, and by whom, and how the necessary level of trust might be obtained. In this paper, by considering existing examples such as the Internet, the possible need for trust is examined in a systematic way, and possible routes to gaining trust are described. The issues that arise when a security and/or reliability failure actually occurs are also discussed. The paper concludes with a discussion of possible future ways of enabling all parties to gain the assurances they need in a cost-effective and harmonised way.

cs.CR

How not to secure wireless sensor networks: A plethora of insecure polynomial-based key pre-distribution schemes

Three closely-related polynomial-based group key pre-distribution schemes have recently been proposed, aimed specifically at wireless sensor networks. The schemes enable any subset of a predefined set of sensor nodes to establish a shared secret key without any communications overhead. It is claimed that these schemes are both secure and lightweight, i.e. making them particularly appropriate for network scenarios where nodes have limited computational and storage capabilities. Further papers have built on these schemes, e.g. to propose secure routing protocols for wireless sensor networks. Unfortunately, as we show in this paper, all three schemes are completely insecure; whilst the details of their operation varies, they share common weaknesses. In every case we show that an attacker equipped with the information built into at most two sensor nodes can compute group keys for all possible groups of which the attacked nodes are not a member, which breaks a fundamental design objective. The attacks can also be achieved by an attacker armed with the information from a single node together with a single group key to which this sensor node is not entitled. Repairing the schemes appears difficult, if not impossible. The existence of major flaws is not surprising given the complete absence of any rigorous proofs of security for the proposed schemes. A further recent paper proposes a group membership authentication and key establishment scheme based on one of the three key pre-distribution schemes analysed here; as we demonstrate, this scheme is also insecure, as the attack we describe on the corresponding pre-distribution scheme enables the authentication process to be compromised.

cs.CR

Yet another insecure group key distribution scheme using secret sharing

A recently proposed group key distribution scheme known as UMKESS, based on secret sharing, is shown to be insecure. Not only is it insecure, but it does not always work, and the rationale for its design is unsound. UMKESS is the latest in a long line of flawed group key distribution schemes based on secret sharing techniques.

cs.CR

The impact of quantum computing on real-world security: A 5G case study

This paper provides a detailed analysis of the impact of quantum computing on the security of 5G mobile telecommunications. This involves considering how cryptography is used in 5G, and how the security of the system would be affected by the advent of quantum computing. This leads naturally to the specification of a series of simple, phased, recommended changes intended to ensure that the security of 5G (as well as 3G and 4G) is not badly damaged if and when large scale quantum computing becomes a practical reality. By exploiting backwards-compatibility features of the 5G security system design, we are able to propose a novel multi-phase approach to upgrading security that allows for a simple and smooth migration to a post-quantum-secure system.

cs.CR

The Saeed-Liu-Tian-Gao-Li authenticated key agreement protocol is insecure

A recently proposed authenticated key agreement protocol is shown to be insecure. In particular, one of the two parties is not authenticated, allowing an active man in the middle opponent to replay old messages. The protocol is essentially an authenticated Diffie-Hellman key agreement scheme, and the lack of authentication allows an attacker to replay old messages and have them accepted. Moreover, if the ephemeral key used to compute a protocol message is ever compromised, then the key established using the replayed message will also be compromised. Fixing the problem is simple - there are many provably secure and standardised protocols which are just as efficient as the flawed scheme.

cs.CR