New Truncated Differential Cryptanalysis on 3D Block Cipher

New Truncated Differential Cryptanalysis on 3D Block Cipher
复制标题

DOI:
10.1007/978-3-642-29101-2_8
复制
发表时间:
2012-04
期刊:
--
影响因子:
--
通讯作者:
Takuma Koyama;Lei Wang;Yu Sasaki;K. Sakiyama;K. Ohta
Takuma Koyama;Lei Wang;Yu Sasaki;K. Sakiyama;K. Ohta
中科院分区:
其他
文献类型:
--
作者:
Takuma Koyama;Lei Wang;Yu Sasaki;K. Sakiyama;K. Ohta

文献摘要

相似文献

针对以往最好的密钥恢复攻击在不可能差分攻击下只能破10轮的情况,提出了基于截断差分分析的3D分组密码11轮和13轮密钥恢复攻击。3D是在CANS 2008上提出的基于AES的分组密码,它在512位块和512位密钥上运行,由22轮组成。以前认为截断差分密码分析不能延长攻击超过5轮。然而,通过仔细分析数据处理部分和密钥调度功能,我们展示了对11轮3D的攻击,2251选择明文(CP),2288计算,2128内存。此外,通过应用早期中止技术,时间复杂度提高到2113。利用中性位的思想,我们用2469个CP,2308个计算和2128个内存攻击了13轮3D。
This paper presents 11- and 13-round key-recovery attacks on block cipher 3D with the truncated differential cryptanalysis, while the previous best key-recovery attack broke only 10 rounds with the impossible differential attack. 3D is an AES-based block cipher proposed at CANS 2008, which operates on 512-bit blocks and a 512-bit key, and consists of 22 rounds. It was previously believed that the truncated differential cryptanalysis could not extend the attack more than 5 rounds. However, by carefully analyzing the data processing part and key schedule function simultaneously, we show the attack to 11-round 3D with 2251chosen plaintext (CP), 2288computations, and 2128memory. Additionally, the time complexity is improved up to 2113by applying the early aborting technique. By utilizing the idea of neutral bit, we attack 13-round 3D with 2469CP, 2308computations, and 2128memory.