Linear hulls with correlation zero and linear cryptanalysis of block ciphers

Linear hulls with correlation zero and linear cryptanalysis of block ciphers
复制标题

DOI:
10.1007/s10623-012-9697-z
复制
发表时间:
2014-03-01
影响因子:
1.6
通讯作者:
Rijmen, Vincent
Rijmen, Vincent
中科院分区:
数学3区
文献类型:
--
作者:
Bogdanov, Andrey;Rijmen, Vincent

文献摘要

被引文献

相似文献

线性密码分析与差分密码分析沿着,是评估分组密码安全性的重要工具。本文介绍了线性密码分析的一种新的扩展:零相关线性密码分析,一种适用于许多分组密码构造的技术。它基于线性近似,相关值恰好为零。对于一个n比特的置换,提出了一个复杂度为2(n-1)的相关性精确计算算法。非平凡的零相关线性近似证明了各种块密码结构,包括AES,平衡Feistel网络,Skipjack,CLEFIA和CAST 256。作为示例,使用零相关线性密码分析,对AES-192和AES-256的6轮以及CLEFIA-256的13轮进行了密钥恢复攻击。
Linear cryptanalysis, along with differential cryptanalysis, is an important tool to evaluate the security of block ciphers. This work introduces a novel extension of linear cryptanalysis: zero-correlation linear cryptanalysis, a technique applicable to many block cipher constructions. It is based on linear approximations with a correlation value of exactly zero. For a permutation on n bits, an algorithm of complexity 2 (n-1) is proposed for the exact evaluation of correlation. Non-trivial zero-correlation linear approximations are demonstrated for various block cipher structures including AES, balanced Feistel networks, Skipjack, CLEFIA, and CAST256. As an example, using the zero-correlation linear cryptanalysis, a key-recovery attack is shown on 6 rounds of AES-192 and AES-256 as well as 13 rounds of CLEFIA-256.