New observation on the key schedule of RECTANGLE

New observation on the key schedule of RECTANGLE
复制标题

DOI:
10.1007/s11432-018-9527-8
复制
发表时间:
2019-01
期刊:
Science China Information Sciences
影响因子:
--
通讯作者:
Hailun Yan;Yiyuan Luo;Mo Chen;Xuejia Lai
Hailun Yan;Yiyuan Luo;Mo Chen;Xuejia Lai
中科院分区:
其他
文献类型:
--
作者:
Hailun Yan;Yiyuan Luo;Mo Chen;Xuejia Lai

文献摘要

被引文献

相似文献

我们从实际密钥信息(阿基)的角度来评估RECTANGLE的安全性。不充分的阿基允许攻击者从一些其他子密钥位推导出一些子密钥位,从而降低整体攻击复杂度或获得更多的攻击轮。通过考虑密钥调度的扩散和轮函数的扩散之间的相互作用,我们发现在RECTANGLE-80和RECTANGLE-128中,尽管主密钥比特分别在2和4轮中实现完全扩散,但在连续4轮和连续6轮中存在阿基不足。利用密钥调度的弱点,我们给出了一个对12轮简化RECTANGLE-128的通用Meet-in-the-middle攻击,其中只有8个已知明文。此外,我们还计算了RECTANGLE和PRESENT的变体的阿基。令人惊讶的是,我们发现矩形-128和PRESENT-128都没有关键的时间表涉及更多的阿基比原来的。在此基础上,我们对RECTANGLE-128的密钥调度做了一些修改。与原始密钥调度相比,新密钥调度在最大化阿基方面与轮函数更好地匹配。本文的工作为分组密码密钥表的设计提供了新的思路。
We evaluate the security of RECTANGLE from the perspective of actual key information (AKI). Insufficient AKI permits the attackers to deduce some subkey bits from some other subkey bits, thereby lowering the overall attack complexity or getting more attacked rounds. By considering the interaction between the key schedule’s diffusion and the round function’s diffusion, we find there exists AKI insufficiency in 4 consecutive rounds for RECTANGLE-80 and 6 consecutive rounds for RECTANGLE-128, although the master key bits achieve complete diffusion in 2 and 4 rounds, respectively. With such weakness of the key schedule, we give a generic meet-in-the-middle attack on 12-round reduced RECTANGLE-128 with only 8 known plaintexts. Moreover, we calculate AKI of variants of RECTANGLE as well as PRESENT. Surprisingly we find that both RECTANGLE-128 and PRESENT-128 with no key schedule involve more AKI than the original one. Based on this finding, we slightly modify the key schedule of RECTANGLE-128. Compared with the original one, this new key schedule matches better with the round function in terms of maximizing AKI. Our work adds more insight to the design of block ciphers’ key schedule.