Impossible Differential Cryptanalysis of Reduced-Round ARIA and Camellia
Impossible Differential Cryptanalysis of Reduced-Round ARIA and Camellia
复制标题
DOI:
10.1007/s11390-007-9056-0
复制
发表时间:
2007-05
影响因子:
0.7
通讯作者:
Wenling Wu;Wentao Zhang;D. Feng
中科院分区:
文献类型:
--
作者:
Wenling Wu;Wentao Zhang;D. Feng
This paper studies the security of the block ciphers ARIA and Camellia against impossible differential cryptanalysis. Our work improves the best impossible differential cryptanalysis of ARIA and Camellia known so far. The designers of ARIA expected no impossible differentials exist for 4-round ARIA. However, we found some nontrivial 4-round impossible differentials, which may lead to a possible attack on 6-round ARIA. Moreover, we found some nontrivial 8-round impossible differentials for Camellia, whereas only 7-round impossible differentials were previously known. By using the 8-round impossible differentials, we presented an attack on 12-round Camellia withoutFL/FL1layers.