Truncated and Multiple Differential Cryptanalysis of Reduced Round Midori128

Truncated and Multiple Differential Cryptanalysis of Reduced Round Midori128
复制标题

DOI:
10.1007/978-3-319-45871-7_1
复制
发表时间:
2016-09
期刊:
--
影响因子:
--
通讯作者:
Mohamed F. Tolba;A. Abdelkhalek;A. Youssef
Mohamed F. Tolba;A. Abdelkhalek;A. Youssef
中科院分区:
其他
文献类型:
--
作者:
Mohamed F. Tolba;A. Abdelkhalek;A. Youssef

文献摘要

被引文献

相似文献

Midori是一个基于spn的轻量级分组密码系列,旨在优化加密和解密操作期间每比特的硬件能耗。在ASIACRYPT 2015上,提出了两种变体,即Midori128和Midori64,分别支持128位密钥和64/128位块。最近,针对Midori64提出了一种中间相遇攻击和一种不变子空间攻击,但这两种攻击都不能应用于Midori128。在本文中,我们提出了截断和多重差分密码分析的轮约化Midori128。我们的分析利用s盒和二元线性变换层的特殊结构,以尽量减少有效s盒的数量。特别地,我们考虑在有源s盒的输入和输出中只包含单个位差的差分。为了在mixcolumopero操作之后保持每个s盒模式的单个位,我们限制了活动s盒输出的位差,它们在shuffle操作之后位于同一列,处于相同的位置。利用这些限制条件,我们能够找到有概率成立的10轮微分。通过在这个差值上面加两轮,在这个差值下面加一轮,我们得到一个13轮截断的差值,并用它来对13轮减少的Midori128执行键恢复攻击。13轮攻击的时间和数据复杂性分别是加密和选择明文。我们还提出了对13轮Midori128的多重差分攻击,分别具有加密和选择明文的时间和数据复杂性。
Midori is a family of SPN-based lightweight block ciphers designed to optimize the hardware energy consumption per bit during the encryption and decryption operations. At ASIACRYPT 2015, two variants of the cipher, namely Midori128 and Midori64, which support a 128-bit secret key and a 64/128-bit block, respectively, were proposed. Recently, a meet-in-the-middle attack and an invariant subspace attack were presented against Midori64 but both attacks cannot be applied to Midori128. In this paper, we present truncated and multiple differential cryptanalysis of round reduced Midori128. Our analysis utilizes the special structure of the S-boxes and binary linear transformation layer in order to minimize the number of active S-boxes. In particular, we consider differentials that contain only single bit differences in the input and output of the active S-boxes. To keep this single bit per S-box patterns after theMixColumnoperation, we restrict the bit differences of the output of the active S-boxes, which lie in the same column after the shuffle operation, to be in the same position. Using these restrictions, we were able to find 10-round differential which holds with probability. By adding two rounds above and one round below this differential, we obtain a 13 round truncated differential and use it to perform a key recovery attack on the 13-round reduced Midori128. The time and data complexities of the 13-round attack areencryptions andchosen plaintext, respectively. We also present a multiple differential attack on the 13-round Midori128, with time and data complexities ofencryptions andchosen plaintext, respectively.