Integral Distinguishers of the Full-Round Lightweight Block Cipher SAT_Jo

Integral Distinguishers of the Full-Round Lightweight Block Cipher SAT_Jo
复制标题

全面轻量级分组密码SAT_Jo的积分判别器

DOI:
10.1155/2021/5310545
复制
发表时间:
2021-09
影响因子:
--
通讯作者:
Enes Pasalic
Enes Pasalic
中科院分区:
计算机科学4区
文献类型:
--
作者:
Xueying Qiu;Yongzhuang Wei;Samir Hodzic;Enes Pasalic

文献摘要

参考文献

相似文献

基于除法性质的积分密码分析是一种强大的密码分析方法,近年来通过混合整数线性规划(MILP)扩展了其成功的应用范围。尽管该技术已被证明可以有效地指定几个轻量级块密码族(如SIMON、PRESENT等)的简化圆形版本的区分符,但我们证明该方法可以为全圆形块密码SAT_Jo提供区分符。SAT_Jo密码与众所周知的PRESENT分组密码非常相似,它已经成功地经受住了已知密码分析方法的考验。与PRESENT相比,SAT_Jo算法的主要区别在于它选择了不同的替换盒(s -box)和位置换层,以使密码具有很高的资源效率,这导致了SAT_Jo算法的严重弱点。尽管设计人员提供了该方案针对一些主要通用密码分析方法的安全性分析,但没有考虑将比特除法特性与MILP结合使用。通过使用此方法为全轮SAT_Jo算法指定积分区分符,我们基本上不赞成在预期的应用程序中使用它。使用30轮区分符,我们还描述了一种针对SAT_Jo算法的子密钥恢复攻击,其时间复杂度约为。2. 66. 加密(注意,SAT_Jo设计为提供80位的安全性)。此外,比特置换的选择似乎导致弱除法性质,因为用PRESENT中使用的比特置换替换SAT_Jo的原始比特置换会立即使积分区分符无效。
Integral cryptanalysis based on division property is a powerful cryptanalytic method whose range of successful applications was recently extended through the use of Mixed-Integer Linear Programming (MILP). Although this technique was demonstrated to be efficient in specifying distinguishers of reduced round versions of several families of lightweight block ciphers (such as SIMON, PRESENT, and few others), we show that this method provides distinguishers for a full-round block cipher SAT_Jo. SAT_Jo cipher is very similar to the well-known PRESENT block cipher, which has successfully withstood the known cryptanalytic methods. The main difference compared to PRESENT, which turns out to induce severe weaknesses of SAT_Jo algorithm, is its different choice of substitution boxes (S-boxes) and the bit-permutation layer for the reasons of making the cipher highly resource-efficient. Even though the designers provided a security analysis of this scheme against some major generic cryptanalytic methods, an application of the bit-division property in combination with MILP was not considered. By specifying integral distinguishers for the full-round SAT_Jo algorithm using this method, we essentially disapprove its use in intended applications. Using a 30-round distinguisher, we also describe a subkey recovery attack on the SAT_Jo algorithm whose time complexity is about . 2. 66. encryptions (noting that SAT_Jo is designed to provide 80 bits of security). Moreover, it seems that the choice of bit-permutation induces weak division properties since replacing the original bit-permutation of SAT_Jo by the one used in PRESENT immediately renders integral distinguishers inefficient.
DOI: 10.1109/iccons.2018.8663068
发表时间: 2018-06
期刊: 2018 Second International Conference on Intelligent Computing and Control Systems (ICICCS)
影响因子: --
作者:
Shantha Mary;Dr. L. Arockiam
通讯作者: Shantha Mary;Dr. L. Arockiam
DOI: 10.1007/978-3-662-46800-5_12
发表时间: 2015-04
期刊: --
影响因子: --
作者:
Yosuke Todo
通讯作者: Yosuke Todo
DOI: 10.1007/978-1-4615-2694-0_23
发表时间: 1994
期刊: --
影响因子: --
作者:
Xuejia Lai
通讯作者: Xuejia Lai
DOI: 10.1007/978-3-642-34704-7_5
发表时间: 2011-11
影响因子: --
作者:
N. Mouha;Qingju Wang;Dawu Gu;B. Preneel
通讯作者: N. Mouha;Qingju Wang;Dawu Gu;B. Preneel
DOI: 10.1007/978-3-642-10433-6_22
发表时间: 2009-11
期刊: --
影响因子: --
作者:
Maryam Izadi;B. Sadeghiyan;S. Sadeghian;Hossein Arabnezhad Khanooki
通讯作者: Maryam Izadi;B. Sadeghiyan;S. Sadeghian;Hossein Arabnezhad Khanooki