Three-Subset Meet-in-the-Middle Attack on Reduced XTEA

Three-Subset Meet-in-the-Middle Attack on Reduced XTEA
复制标题

DOI:
10.1007/978-3-642-31410-0_9
复制
发表时间:
2012-07
期刊:
--
影响因子:
--
通讯作者:
Yu Sasaki;Lei Wang;Yasuhide Sakai;K. Sakiyama;K. Ohta
Yu Sasaki;Lei Wang;Yasuhide Sakai;K. Sakiyama;K. Ohta
中科院分区:
其他
文献类型:
--
作者:
Yu Sasaki;Lei Wang;Yasuhide Sakai;K. Sakiyama;K. Ohta

文献摘要

相似文献

提出了一种改进的基于三子集中间相遇(MitM)的分组密码XTEA单密钥攻击。首先,讨论了一种通用分组密码技术。指出了以往的工作应用拼接切割技术的三子集的MitM攻击包含不完整的参数,因此它需要非常大的数据复杂度,这是接近的代码书。本文给出了一个修正的过程,以保持数据的复杂性小。其次,对具有64轮Feistel网络和128位密钥的64位分组密码XTEA进行了三子集MitM攻击。使用9个已知明文和2120.40XTEA计算攻击25轮,而之前最好的单密钥攻击仅达到23轮。在选择明文模型下,攻击扩展到28轮,237个选择明文和2120.38次计算。
This paper presents an improved single-key attack on a block-cipher XTEA by using the three-subset meet-in-the-middle (MitM) attack. Firstly, a technique on a generic block-cipher is discussed. It points out that the previous work applying the splice-and-cut technique to the three-subset MitM attack contains incomplete arguments, and thus it requires a very large data complexity, which is close to the code book. This paper gives a corrected procedure to keep the data complexity small. Secondly, the three-subset MitM attack is applied for reduced-round XTEA, which is a 64-bit block-cipher with 64-round Feistel network and a 128-bit key. 25 rounds are attacked with 9 known plaintexts and 2120.40XTEA computations, while the previous best single-key attack only reaches 23 rounds. In the chosen-plaintext model, the attack is extended to 28 rounds with 237chosen-plaintexts and 2120.38computations.