Weak rotational property and its application

Weak rotational property and its application
复制标题

DOI:
10.1007/s10623-023-01241-5
复制
发表时间:
2023-06
期刊:
Designs, Codes and Cryptography
影响因子:
--
通讯作者:
Kai Zhang;Xuejia Lai;Jie Guan;B. Hu
Kai Zhang;Xuejia Lai;Jie Guan;B. Hu
中科院分区:
其他
文献类型:
--
作者:
Kai Zhang;Xuejia Lai;Jie Guan;B. Hu

文献摘要

相似文献

随着密码分析技术的快速发展,多区分攻击逐渐出现。多重差分密码分析、多重线性密码分析、多重不可能差分密码分析、多维零相关线性密码分析等新的密码分析方法被提出,极大地提高了相应攻击的效率。在这些攻击中,发现更多的区分一直是一项琐碎的手工工作。许多密码学家利用他们的专业知识和经验来实现这一目标。然而,在大多数情况下,攻击的长度或区分者的数量被低估了。本文提出了一种基于“弱旋转性质”发现更多不同区分符的通用方法。具有这一性质的分组密码可以很容易地从理论上发现更多的区分器,如截断的微分区分器、不可能的区分器和零相关的线性区分器。然后,用数学形式证明了等价判别器的数目。作为应用,本文以西蒙族密码为例说明这一性质是如何改进密码分析的。在应用部分,首先证明了西蒙族密码具有弱旋转性。因此,可以为西蒙增加相应发现的识别符的数量。然后,将先前对Simon的一些观察结果相应地推广到这一新性质。最后,基于弱旋转性的思想和等价子密钥技术,提出了一种改进的SIMON不可能差分密码分析。对于SIMON32()/SIMON128(128)/SIMON128(192),攻击的回合都延长了一轮。对于Simon的其他变体,推导了当前最好的非完全码本不可能差分攻击。弱旋转性质的成功应用表明了它在密码分析中的潜力。
With the rapid evolvement of cryptanalysis, attacks with multiple distinguishers have emerged gradually. Many new cryptanalytic methods such as multiple differential cryptanalysis, multiple linear cryptanalysis, multiple impossible differential cryptanalysis, multidimensional zero correlation linear cryptanalysis have been proposed, which have greatly enhanced the efficiency of corresponding attacks. During these attacks, discovering more distinguishers has always been a trivial and manual work. Many cryptographers use their expertise and experience to achieve this goal. However, in most cases, either the length of the attack or the number of distinguishers is underestimated. This paper proposes a generic method to discover more different distinguishers based on a new property called “weak rotational property”. Block ciphers with this property can easily discover more distinguishers such as truncated differential distinguishers, impossible differential distinguishers and zero correlation linear distinguishers in a theoretical approach. Then the number of equivalent distinguishers is proved in a mathematical form. As an application, this paper focuses on SIMON family ciphers to illustrate how this property improves cryptanalysis. For the section of application, first of all, SIMON family ciphers are proved to have weak rotational property. Thus the number of corresponding discovered distinguishers can be increased for SIMON. Then, some earlier observations on SIMON are extended accordingly to this new property. Finally, based on the idea of weak rotational property and equivalent-subkey technique, an improved impossible differential cryptanalysis on SIMON is proposed. For SIMON32(64)/SIMON128(128)/SIMON128(192), the rounds attacked are all extended by one round. For other variants of SIMON, current best non full codebook impossible differential attacks are derived. The successful application of weak rotational property indicates its potential in cryptanalysis.