Secure key-alternating Feistel ciphers without key schedule
Secure key-alternating Feistel ciphers without key schedule
复制标题
无需密钥时间表的安全密钥交替 Feistel 密码
DOI:
10.1007/s11432-019-9938-0
复制
发表时间:
2020-10
期刊:
影响因子:
--
通讯作者:
Lai Xuejia
中科院分区:
文献类型:
--
作者:
Shen Yaobin;Yan Hailun;Wang Lei;Lai Xuejia
Blockciphers play an fundamental role for cryptography in information security, which usually consist of round functions and key schedules. As one of the significant modules in blockciphers, key schedules have not received deserved attention. Commonly, the key schedule takes as input a master key and outputs the so-called round keys that are used in each round. In the case of AES-128, the master key is a 128-bit string and the total length of the round keys is 11× 128= 1408 bits. The AES-128 key schedule can be seen as a function from {0, 1} 128 to {0, 1} 1408. Scientifically designing the key schedule part of block ciphers is an important but not well-understood subject. In general, it is not yet clear what practical and necessary principles a good key schedule has to follow. In order to resist some existing attacks, there are some properties on what a key schedule should not have, eg, avoiding (semi-) weak keys, equivalent keys, symmetry and complementation properties [1]. Moreover, it should not be possible to mount trivial guess-and-determine attack attacks, meet-in-the-middle attacks, related-key attacks, slide-attacks or invariant subspace attacks. Considering the key schedule from the view of provable security is another direction. Chen et al.[2] used a lovely key schedule instantiated with a linear orthomorphism to minimize a two-round Even-Mansour cipher from just one n-bit master key and one n-bit permutation. They proved such AES-like construction can achieve beyond the birthday bound security. Recently, Guo and Wang (GW)[3] also used a linear-orthomorphism key schedule to obtain a birthdaybound secure four-round key-alternating Feistel (KAF) cipher from just one n-bit master key and one n-bit function. They claimed this four-round construction is theoretically minimal in the sense that removing any component of this construction would ruin the security. In addition to providing necessary cryptographic security, the efficiency of the key schedule is also of great significance, especially for lightweight blockciphers which are often employed in source constrained environments such as radio-frequency identification (RFID) tags and sensor networks. In these lightweight ciphers, key schedules are commonly highly simplified to optimize the software and hardware efficiency. Some key schedules have round-by-round iterations with low diffusion [4, 5], or do simple permutation or linear operations on master keys [6]. In particular, some lightweight ciphers have ultra-light (in fact non-existent) key schedule, and directly use master keys in each round [7, 8].• Our contributions. We start with an interesting question of how to design a as light as possible key schedule from the view of provable security and revisit the four-round KAF by GW (see Figure 1 (a)). Although the key schedule instantiated with linear orthomorphism can be efficient in some instances, it is still unsatisfying for lightweight ciphers when applied in many source constrained environments. In this study, we optimize the construction by GW and propose a new four-round KAF with an ultra-light (non-existent) key schedule. Interestingly, we find the orthomorphism in their construction can be removed with a slight modification on the first round, ie, applying one-bit rotation after the first round function. We prove this refined construction can achieve the birthday-bound security. Compared with GW’s construction, our proposal has two advantages. The most significant one is that the key schedule is ultralight (non-existent), which needs no computation/memory costs. One can simply bitwise exclusive-or (xor) the n-bit master key in corresponding rounds without bothering to any round-key derive …
登录
查看更多内容
DOI:
10.1007/978-3-642-17401-8_7
发表时间:
2010-12
期刊:
--
影响因子:
--
作者:
M. Nandi
通讯作者:
M. Nandi
DOI:
10.1007/978-3-030-03326-2_8
发表时间:
2018-12
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
作者:
Chun Guo;Lei Wang
通讯作者:
Chun Guo;Lei Wang
影响因子:
4.6
作者:
A. Bogdanov;L. Knudsen;G. Leander;C. Paar;A. Poschmann;M. Robshaw;Y. Seurin;C. Vikkelsoe
通讯作者:
A. Bogdanov;L. Knudsen;G. Leander;C. Paar;A. Poschmann;M. Robshaw;Y. Seurin;C. Vikkelsoe
DOI:
10.1007/s11432-018-9527-8
发表时间:
2019-01
期刊:
Science China Information Sciences
影响因子:
--
作者:
Hailun Yan;Yiyuan Luo;Mo Chen;Xuejia Lai
通讯作者:
Hailun Yan;Yiyuan Luo;Mo Chen;Xuejia Lai
DOI:
--
发表时间:
2002-02
期刊:
--
影响因子:
--
作者:
J. Daemen;V. Rijmen
通讯作者:
J. Daemen;V. Rijmen