New Multiset Attacks on Rijndael with Large Blocks

New Multiset Attacks on Rijndael with Large Blocks
复制标题

DOI:
10.1007/11554868_20
复制
发表时间:
2005-09
期刊:
--
影响因子:
--
通讯作者:
Jorge Nakahara;Daniel Santana de Freitas;R. Phan
Jorge Nakahara;Daniel Santana de Freitas;R. Phan
中科院分区:
其他
文献类型:
--
作者:
Jorge Nakahara;Daniel Santana de Freitas;R. Phan

文献摘要

被引文献

相似文献

本文首次对分组长度大于128位的Rijndael密码进行了安全性评估。我们描述了新的高阶多重集的Rijndael这样的大块的实例。Rijndael和AES都被设计为抵抗差分和线性密码分析,这通过最佳差分和线性密码分析的有效S盒数量(4轮AES最少25个)来表示,其概率和相关值估计为2− 150和2− 75。所有这些Rijndael变体都被其设计者正式定义为AES的扩展。我们描述了Rijndael的新的5轮排序器,具有160到256位的块,所有块都具有确定性,并且具有超过25个活动S盒。
This paper presents the first security evaluation of theRijndael cipher with block sizes larger than 128 bits. We describe new higher-order multiset distinguishers for such large-block instances of Rijndael. Both Rijndael and the AES were designed to resist differential and linear cryptanalysis, which is indicated by the number of active S-boxes (minimum of 25 for 4-round AES) for the best differential and linear distinguishers, for which the probability and correlation values are estimated as 2− 150and 2− 75. All of these Rijndael variants have been formally defined by their designers as extensions of the AES. We describe new 5-round distinguishers for Rijndael with 160 up to 256-bit blocks, all holding with certainty, and with many more than 25 active S-boxes.