Impossible differential cryptanalysis using matrix method

Impossible differential cryptanalysis using matrix method
复制标题

DOI:
10.1016/j.disc.2009.10.019
复制
发表时间:
2010-03
期刊:
Discret. Math.
影响因子:
--
通讯作者:
Jongsung Kim;Seokhie Hong;Jongin Lim
Jongsung Kim;Seokhie Hong;Jongin Lim
中科院分区:
其他
文献类型:
--
作者:
Jongsung Kim;Seokhie Hong;Jongin Lim

文献摘要

被引文献

相似文献

不可能差分密码分析的一般策略是首先找到不可能差分,然后利用它们从分组密码的外轮中检索子密钥材料。因此,不可能差分是衡量分组密码抵抗不可能差分分析能力的关键因素之一。在这篇文章中,我们介绍了一个广泛适用的矩阵方法来寻找分组密码结构的轮函数是双射的不可能微分。利用这种方法,我们找到了已知分组密码结构的各种不可能微分:Nyberg的广义Feistel网络,广义类CAST256结构,广义类MARS结构,广义类RC6结构,Rijndael结构和广义类Skipjack结构。我们希望本文中开发的矩阵方法将是有用的评估对不可能的差分密码分析的分组密码的安全性,特别是当人们试图设计一个分组密码的安全结构。
The general strategy of impossible differential cryptanalysis is to first find impossible differentials and then exploit them for retrieving subkey material from the outer rounds of block ciphers. Thus, impossible differentials are one of the crucial factors to see how much the underlying block ciphers are resistant to impossible differential cryptanalysis. In this article, we introduce a widely applicable matrix method to find impossible differentials of block cipher structures whose round functions are bijective. Using this method, we find various impossible differentials of known block cipher structures: Nyberg’s generalized Feistel network, a generalized CAST256-like structure, a generalized MARS-like structure, a generalized RC6-like structure, Rijndael structures and generalized Skipjack-like structures. We expect that the matrix method developed in this article will be useful for evaluating the security of block ciphers against impossible differential cryptanalysis, especially when one tries to design a block cipher with a secure structure.