The higher-order meet-in-the-middle attack and its application to the Camellia block cipher

The higher-order meet-in-the-middle attack and its application to the Camellia block cipher
复制标题

DOI:
10.1016/j.tcs.2014.01.031
复制
发表时间:
2012-12
期刊:
--
影响因子:
--
通讯作者:
Jiqiang Lu;Yongzhuang Wei;Jongsung Kim;E. Pasalic
Jiqiang Lu;Yongzhuang Wei;Jongsung Kim;E. Pasalic
中科院分区:
其他
文献类型:
--
作者:
Jiqiang Lu;Yongzhuang Wei;Jongsung Kim;E. Pasalic

文献摘要

被引文献

相似文献

Camellia分组密码具有128位块长度,128、192或256位长的用户密钥,128位密钥总共有18轮,192或256位密钥总共有24轮。它是日本CRYPTREC推荐的电子政务密码、欧洲尼斯选择的密码和ISO国际标准。中间相遇攻击是一种分析分组密码安全性的技术。本文提出了一种扩展的中间相遇攻击,称为高阶中间相遇攻击,其核心思想是在构造一个基本的“中间值”单元时,使用多个明文来删除某些依赖于密钥的成分(S)或参数(S)。然后,我们提出了一种新的方法,将积分密码分析和中间相遇攻击相结合,构造了对10轮CAMELIA的HO-MITM攻击,其中FL/FL−1函数在128个密钥比特下,11轮CAMELIA在192个密钥比特下FL/FL−1函数,12轮CAMELIA在256个密钥比特下FL/FL−1函数。最后,我们应用已有的方法在192个密钥比特下对没有FL/FL−1函数的14轮Camellia和在256个密钥比特下没有FL/FL−1函数的16轮Camellia构造了HO-MITM攻击。HO-MITM攻击可能被用来对其他分组密码进行密码分析。
The Camellia block cipher has a 128-bit block length, a user key of 128, 192 or 256 bits long, and a total of 18 rounds for a 128-bit key and 24 rounds for a 192 or 256-bit key. It is a Japanese CRYPTREC-recommended e-government cipher, a European NESSIE selected cipher and an ISO international standard. The meet-in-the-middle attack is a technique for analysing the security of a block cipher. In this paper, we propose an extension of the meet-in-the-middle attack, which we call the higher-order meet-in-the-middle (HO-MitM) attack; the core idea of the HO-MitM attack is to use multiple plaintexts to cancel some key-dependent component (s) or parameter (s) when constructing a basic unit of “value-in-the-middle”. Then we introduce a novel approach, which combines integral cryptanalysis with the meet-in-the-middle attack, to construct HO-MitM attacks on 10-round Camellia with the FL/FL− 1 functions under 128 key bits, 11-round Camellia with the FL/FL− 1 functions under 192 key bits and 12-round Camellia with the FL/FL− 1 functions under 256 key bits. Finally, we apply an existing approach to construct HO-MitM attacks on 14-round Camellia without the FL/FL− 1 functions under 192 key bits and 16-round Camellia without the FL/FL− 1 functions under 256 key bits. The HO-MitM attack can potentially be used to cryptanalyse other block ciphers.