New Multiset Attacks on Rijndael with Large Blocks
New Multiset Attacks on Rijndael with Large Blocks
复制标题
DOI:
10.1007/11554868_20
复制
发表时间:
2005-09
期刊:
影响因子:
--
通讯作者:
Jorge Nakahara;Daniel Santana de Freitas;R. Phan
中科院分区:
文献类型:
--
作者:
Jorge Nakahara;Daniel Santana de Freitas;R. Phan
This paper presents the first security evaluation of theRijndael cipher with block sizes larger than 128 bits. We describe new higher-order multiset distinguishers for such large-block instances of Rijndael. Both Rijndael and the AES were designed to resist differential and linear cryptanalysis, which is indicated by the number of active S-boxes (minimum of 25 for 4-round AES) for the best differential and linear distinguishers, for which the probability and correlation values are estimated as 2− 150and 2− 75. All of these Rijndael variants have been formally defined by their designers as extensions of the AES. We describe new 5-round distinguishers for Rijndael with 160 up to 256-bit blocks, all holding with certainty, and with many more than 25 active S-boxes.