Automated Search Oriented to Key Recovery on Ciphers with Linear Key Schedule: Applications to Boomerangs in SKINNY and ForkSkinny

Automated Search Oriented to Key Recovery on Ciphers with Linear Key Schedule: Applications to Boomerangs in SKINNY and ForkSkinny
复制标题

面向线性密钥调度密码密钥恢复的自动搜索

DOI:
10.46586/tosc.v2021.i2.249-291
复制
发表时间:
2021
期刊:
IACR Trans. Symmetric Cryptol.
影响因子:
--
通讯作者:
Yunwen Liu
Yunwen Liu
中科院分区:
其他
文献类型:
--
作者:
Lingyue Qin;Xiaoyang Dong;Xiaoyun Wang;Keting Jia;Yunwen Liu

文献摘要

相似文献

自动建模搜索具有高概率覆盖尽可能多轮的随机数,如MILP,SAT/SMT,CP模型,已成为当今密码分析的一个非常热门的课题。在这些模型中,优化目标通常是决策者的概率或轮数。如果我们想要恢复用于轮缩减分组密码的秘密密钥,通常有两个阶段,即,找到一个有效的密钥恢复算法,并在密钥恢复算法前后延长几轮进行密钥恢复攻击。攻击回合的总数不仅与所选择的攻击回合有关,还与攻击回合前后的扩展回合有关。在本文中,我们试图将这两个阶段结合在一个统一的自动模型中。具体地说,我们应用这一思想自动化的相关关键矩形攻击的SKINNY和ForkSkinny。我们提出了一些新的攻击者的优势,执行密钥恢复攻击。我们对几个版本的roundreduced SKINNY和ForkSkinny的密钥恢复攻击比以前最好的攻击多覆盖1到2轮。
Automatic modelling to search distinguishers with high probability covering as many rounds as possible, such as MILP, SAT/SMT, CP models, has become a very popular cryptanalysis topic today. In those models, the optimizing objective is usually the probability or the number of rounds of the distinguishers. If we want to recover the secret key for a round-reduced block cipher, there are usually two phases, i.e., finding an efficient distinguisher and performing key-recovery attack by extending several rounds before and after the distinguisher. The total number of attacked rounds is not only related to the chosen distinguisher, but also to the extended rounds before and after the distinguisher. In this paper, we try to combine the two phases in a uniform automatic model. Concretely, we apply this idea to automate the related-key rectangle attacks on SKINNY and ForkSkinny. We propose some new distinguishers with advantage to perform key-recovery attacks. Our key-recovery attacks on a few versions of roundreduced SKINNY and ForkSkinny cover 1 to 2 more rounds than the best previous attacks.