Linear hulls with correlation zero and linear cryptanalysis of block ciphers
Linear hulls with correlation zero and linear cryptanalysis of block ciphers
复制标题
DOI:
10.1007/s10623-012-9697-z
复制
发表时间:
2014-03-01
影响因子:
1.6
通讯作者:
Rijmen, Vincent
中科院分区:
文献类型:
--
作者:
Bogdanov, Andrey;Rijmen, Vincent
Linear cryptanalysis, along with differential cryptanalysis, is an important tool to evaluate the security of block ciphers. This work introduces a novel extension of linear cryptanalysis: zero-correlation linear cryptanalysis, a technique applicable to many block cipher constructions. It is based on linear approximations with a correlation value of exactly zero. For a permutation on n bits, an algorithm of complexity 2 (n-1) is proposed for the exact evaluation of correlation. Non-trivial zero-correlation linear approximations are demonstrated for various block cipher structures including AES, balanced Feistel networks, Skipjack, CLEFIA, and CAST256. As an example, using the zero-correlation linear cryptanalysis, a key-recovery attack is shown on 6 rounds of AES-192 and AES-256 as well as 13 rounds of CLEFIA-256.