Construction of Recursive MDS Diffusion Layers from Gabidulin Codes

Construction of Recursive MDS Diffusion Layers from Gabidulin Codes
复制标题

DOI:
10.1007/978-3-319-03515-4_18
复制
发表时间:
2013-12
期刊:
--
影响因子:
--
通讯作者:
T. Berger
T. Berger
中科院分区:
其他
文献类型:
--
作者:
T. Berger

文献摘要

被引文献

相似文献

许多最近的分组密码在其扩散层中使用最大距离可分离(MDS)矩阵。该操作的主要目标是尽可能地扩展非线性Sbox的输出之间的差异。因此,它们通常在半字节或字节级别上起作用。MDS矩阵与比率为1/2的MDS码相关联。最著名的例子是AES分组密码的MixColumns运算。在这个例子中,MDS矩阵被仔细选择,以获得紧凑和高效的软件和硬件实现。然而,该MDS矩阵专用于8位字,并且并不总是适于轻量级应用。最近,一些研究已经致力于递归扩散层的建设。这种方法允许使用迭代过程来应用MDS矩阵,该迭代过程看起来像是具有线性函数而不是非线性函数的Feistel网络。本文提出了一种MDS递归扩散层的通用构造,如[1],[7],[10],[12],[15]中所提出的,但将这种构造与Gabidulin码理论联系起来。该构造使用具有不仅是MDS而且是MRD(最大秩距离)的性质的Gabidulin码。这一事实给扩散层提供了一个额外的属性,这似乎对加密应用很有趣。
Many recent block ciphers use Maximum Distance Separable (MDS) matrices in their diffusion layer. The main objective of this operation is to spread as much as possible the differences between the outputs of nonlinear Sboxes. So they generally act at nibble or at byte level. The MDS matrices are associated to MDS codes of ratio 1/2. The most famous example is the MixColumns operation of the AES block cipher.In this example, the MDS matrix was carefully chosen to obtain compact and efficient implementations in software and hardware. However, this MDS matrix is dedicated to 8-bit words, and is not always adapted to lightweight applications. Recently, several studies have been devoted to the construction of recursive diffusion layers. Such a method allows to apply an MDS matrix using an iterative process which looks like a Feistel network with linear functions instead of nonlinear.In this paper, we present a generic construction of MDS recursive diffusion layers as proposed in [1], [7], [10], [12], [15] but bridging this construction with the theory of Gabidulin codes. This construction uses Gabidulin codes which have the property to be not only MDS but also MRD (Maximum Rank Distance). This fact gives an additional property to diffusion layers which seems interesting for cryptographic applications.