Improved Multidimensional Zero-Correlation Linear Cryptanalysis and Applications to LBlock and TWINE

Improved Multidimensional Zero-Correlation Linear Cryptanalysis and Applications to LBlock and TWINE
复制标题

DOI:
10.1007/978-3-319-08344-5_1
复制
发表时间:
2014-07
期刊:
--
影响因子:
--
通讯作者:
Yanfeng Wang;Wenling Wu
Yanfeng Wang;Wenling Wu
中科院分区:
其他
文献类型:
--
作者:
Yanfeng Wang;Wenling Wu

文献摘要

被引文献

相似文献

零相关线性密码分析是一种基于相关为零的线性近似的新方法。本文通过考虑轮密钥的等价关系,提出了一种新的多维零相关线性密码分析模型。改进的攻击模型首先找出所有最长的多维零相关线性区分器,然后将独立猜测密钥最少的区分器作为最优的区分器,最后利用部分压缩技术选择一个最优的区分器来恢复密码的密钥。基于改进的攻击模型,对原有的22轮零相关线性攻击进行了扩展,并针对零相关线性密码分析对TWINE攻击的安全性进行了评估。至少有8×8类多维零相关线性鉴别器用于14轮LBlock和TWINE。在确定了相应的最优区分器后,我们仔细选择猜测密钥的顺序,逐一猜测每个子密钥,实现了对23轮LBlock的攻击、对23轮TWINE-80的攻击和对25轮TWINE-128的另一次攻击。据我们所知,这些结果是目前LBlock和TWINE在单键场景下的最好结果,除了优化的蛮力攻击。
Zero-correlation linear cryptanalysis is a new method based on the linear approximations with correlation zero. In this paper, we propose a new model of multidimensional zero-correlation linear cryptanalysis by taking the equivalent relations of round keys into consideration. The improved attack model first finds out all the longest multidimensional zero-correlation linear distinguishers, then regards the distinguishers with the least independent guessed keys as the optimal distinguishers and finally chooses one optimal distinguisher to recover the secret key of cipher by using the partial-compression technique. Based on the improved attack model, we extend the original 22-round zero-correlation linear attack on LBlock and first evaluate the security of TWINE against the zero-correlation linear cryptanalysis. There are at least 8×8 classes of multidimensional zero-correlation linear distinguishers for 14-round LBlock and TWINE. After determining the corresponding optimal distinguisher, we carefully choose the order of guessing keys and guess each subkey nibble one after another to achieve an attack on 23-round LBlock, an attack on 23-round TWINE-80 and another attack on 25-round TWINE-128. As far as we know, these results are the currently best results on LBlock and TWINE in the single key scenario except the optimized brute force attack.