An Upper Bound of the Longest Impossible Differentials of Several Block Ciphers

An Upper Bound of the Longest Impossible Differentials of Several Block Ciphers
复制标题

几种分组密码的最长不可能差分的上界

DOI:
10.3837/tiis.2019.01.024
复制
发表时间:
2019
影响因子:
1.5
通讯作者:
Zhao Hongluan
Zhao Hongluan
中科院分区:
计算机科学4区
文献类型:
--
作者:
Han Guoyong;Zhang Wenying;Zhao Hongluan

文献摘要

被引文献

相似文献

不可能差分密码分析是一种重要的密码分析技术,其关键在于是否存在不可能差分路径,影响不可能差分密码分析的主要因素是不可能差分路径的轮数,因为轮数越大,攻击越接近于真实的加密算法。给出了几个重要分组密码的最长不可能差分迹的上界。我们首先分析了2015年俄罗斯联邦的国家标准Kuznyechik,该标准利用16字节LFSR来实现线性变换。我们的结论是,没有任何3轮不可能的差分线索的Kuznyechik不考虑特定的S盒。然后利用矩阵方法确定了其他几个重要分组密码的最长不可能差分路径,该方法可以推广到其他分组密码。结果表明,在不考虑S盒细节的情况下,KLEIN、Midori64和MIBS分别不存在大于或等于5轮、7轮和9轮的不可能差分路.
Impossible differential cryptanalysis is an essential cryptanalytic technique and its key point is whether there is an impossible differential path. The main factor of influencing impossible differential cryptanalysis is the length of the rounds of the impossible differential trail because the attack will be more close to the real encryption algorithm with the number becoming longer. We provide the upper bound of the longest impossible differential trails of several important block ciphers. We first analyse the national standard of the Russian Federation in 2015, Kuznyechik, which utilizes the 16-byte LFSR to achieve the linear transformation. We conclude that there is no any 3-round impossible differential trail of the Kuznyechik without the consideration of the specific S-boxes. Then we ascertain the longest impossible differential paths of several other important block ciphers by using the matrix method which can be extended to many other block ciphers. As a result, we show that, unless considering the details of the S-boxes, there is no any more than or equal to 5-round, 7-round and 9-round impossible differential paths for KLEIN, Midori64 and MIBS respectively.