Structural Evaluation by Generalized Integral Property

Structural Evaluation by Generalized Integral Property
复制标题

DOI:
10.1007/978-3-662-46800-5_12
复制
发表时间:
2015-04
期刊:
--
影响因子:
--
通讯作者:
Yosuke Todo
Yosuke Todo
中科院分区:
其他
文献类型:
--
作者:
Yosuke Todo

文献摘要

被引文献

相似文献

在本文中,我们展示了两种流行的网络,即Feistel网络和替代置换网络(SPN)的结构密码分析。我们的密码分析是通过改进的积分区分器来区分攻击。积分区分符是对分组密码最有效的攻击之一,它通常是通过评估积分属性的传播特性来构建的,例如ALL或BALANCE属性。然而,对于具有非双目标函数和位结构的分组密码,该积分性质不能推导出有用的区分符。此外,由于积分性质没有清楚地利用分组密码的代数次,它往往不能构造出对具有低次函数的分组密码有用的区分符。本文提出了一个新的性质——除法性质,它是积分性质的推广。即使分组密码具有非双目标函数、位结构和低次函数,也能有效地构造积分区分符。从可攻击的轮数或选择明文的角度来看,除法属性可以构造出比以往方法更好的区分符。虽然我们的攻击是一种通用攻击,但它可以改进针对特定密码原语的几个积分区分符。例如,它可以减少keccak -fromto的轮分隔符所选择的明文的数量。对于Feistel密码,它从理论上证明了simon32、48、64、96和128分别具有-、-、-、-和整数区分符。
In this paper, we show structural cryptanalyses against two popular networks, i.e., the Feistel Network and the Substitute-Permutation Network (SPN). Our cryptanalyses are distinguishing attacks by an improved integral distinguisher. The integral distinguisher is one of the most powerful attacks against block ciphers, and it is usually constructed by evaluating the propagation characteristic of integral properties, e.g., the ALL or BALANCE property. However, the integral property does not derive useful distinguishers against block ciphers with non-bijective functions and bit-oriented structures. Moreover, since the integral property does not clearly exploit the algebraic degree of block ciphers, it tends not to construct useful distinguishers against block ciphers with low-degree functions. In this paper, we propose a new property calledthe division property, which is the generalization of the integral property. It can effectively construct the integral distinguisher even if the block cipher has non-bijective functions, bit-oriented structures, and low-degree functions. From viewpoints of the attackable number of rounds or chosen plaintexts, the division property can construct better distinguishers than previous methods. Although our attack is a generic attack, it can improve several integral distinguishers against specific cryptographic primitives. For instance, it can reduce the required number of chosen plaintexts for the-round distinguisher onKeccak-fromto. For the Feistel cipher, it theoretically proves thatSimon32, 48, 64, 96, and 128 have-,-,-,-, and-round integral distinguishers, respectively.