A Related-Key Rectangle Attack on the Full KASUMI

A Related-Key Rectangle Attack on the Full KASUMI
复制标题

DOI:
10.1007/11593447_24
复制
发表时间:
2005-12
期刊:
--
影响因子:
--
通讯作者:
E. Biham;O. Dunkelman;Nathan Keller
E. Biham;O. Dunkelman;Nathan Keller
中科院分区:
其他
文献类型:
--
作者:
E. Biham;O. Dunkelman;Nathan Keller

文献摘要

被引文献

相似文献

KASUMI是用于3GPP移动的通信的机密性和完整性算法的8轮Feistel分组密码。随着越来越多的3GPP网络被部署,越来越多的用户使用KASUMI来保护他们的隐私。以前已知的攻击KASUMI可以打破6出8轮比穷举密钥搜索更快,并没有攻击完整KASUMI已经published.In本文中,我们应用最近推出的相关密钥回旋镖和矩形攻击KASUMI,导致攻击速度比穷举搜索对完整的密码。我们还提出了一个相关的密钥回旋镖算法6轮KASUMI只使用768个自适应选择的明文和密文加密或解密下的四个相关keys.Recently,它表明,整个加密系统的3GPP网络的安全性不能证明只使用“普通”的假设,基础密码(KASUMI)是一个伪随机置换。它还表明,如果我们假设KASUMI也是安全的,相对于基于差分的相关密钥攻击,那么整个系统的安全性可以被证明。我们的研究结果表明,理论上,KASUMI对于基于差分的相关密钥攻击是不安全的,因此,3GPP的整个加密系统的安全性此时无法得到证明。
KASUMI is an 8-round Feistel block cipher used in the confidentiality and the integrity algorithms of the 3GPP mobile communications. As more and more 3GPP networks are being deployed, more and more users use KASUMI to protect their privacy. Previously known attacks on KASUMI can break up to 6 out of the 8 rounds faster than exhaustive key search, and no attacks on the full KASUMI have been published.In this paper we apply the recently introduced related-key boomerang and rectangle attacks to KASUMI, resulting in an attack that is faster than exhaustive search against the full cipher. We also present a related-key boomerang distinguisher for 6-round KASUMI using only 768 adaptively chosen plaintexts and ciphertexts encrypted or decrypted under four related keys.Recently, it was shown that the security of the entire encryption system of the 3GPP networks cannot be proven using only the “ordinary” assumption that the underlying cipher (KASUMI) is a Pseudo-Random Permutation. It was also shown that if we assume that KASUMI is also secure with respect to differential-based related-key attacks then the security of the entire system can be proven. Our results show that theoretically, KASUMI is not secure with respect to differential-based related-key attacks, and thus, the security of the entire encryption system of the 3GPP cannot be proven at this time.