Progress in Cryptology - INDOCRYPT 2005, 6th International Conference on Cryptology in India, Bangalore, India, December 10-12, 2005, Proceedings

Progress in Cryptology - INDOCRYPT 2005, 6th International Conference on Cryptology in India, Bangalore, India, December 10-12, 2005, Proceedings
复制标题

DOI:
10.1007/11596219
复制
发表时间:
2005
期刊:
--
影响因子:
--
通讯作者:
S. Maitra;C. Madhavan;R. Venkatesan
S. Maitra;C. Madhavan;R. Venkatesan
中科院分区:
其他
文献类型:
--
作者:
S. Maitra;C. Madhavan;R. Venkatesan

文献摘要

被引文献

相似文献

Dragon 是提交给 ECRYPT 项目的面向字的​​流密码,它在 128 和 256 位的密钥大小上运行。设计的最初想法是使用非线性反馈移位寄存器(NLFSR)和线性部分(计数器),通过滤波器功能组合来生成NLFSR的新状态并产生密钥流。密码的内部状态为1088位,即任何类型的TMD攻击都不适用。在本文中,我们提出了两个统计区分器,将 Dragon 与随机源区分开来,两者都需要密钥流的大约 O(2155) 个单词。在第一种情况下,时间复杂度约为 O(2155 + 32),内存复杂度为 O(232),而第二种情况只需要 O(2155) 时间,但需要 O(296) 内存。该攻击基于过滤函数 F 引入密钥流的统计弱点。这是第一篇提出对 Dragon 的攻击的论文,它表明当使用 256 位大小的密钥时,该密码不能提供完全的安全性。
Dragon is a word oriented stream cipher submitted to the ECRYPT project, it operates on key sizes of 128 and 256 bits. The original idea of the design is to use a nonlinear feedback shift register (NLFSR) and a linear part (counter), combined by a filter function to generate a new state of the NLFSR and produce the keystream. The internal state of the cipher is 1088 bits, i.e., any kinds of TMD attacks are not applicable. In this paper we present two statistical distinguishers that distinguish Dragon from a random source both requiring aroundO(2155) words of the keystream. In the first scenario the time complexity is aroundO(2155 + 32) with the memory complexityO(232), whereas the second scenario needs onlyO(2155) of time, butO(296) of memory. The attack is based on a statistical weakness introduced into the keystream by the filter functionF. This is the first paper presenting an attack on Dragon, and it shows that the cipher does not provide full security when the key of size 256 bits is used.