New Meet-in-the-Middle Attacks on FOX Block Cipher

New Meet-in-the-Middle Attacks on FOX Block Cipher
复制标题

针对 FOX 分组密码的新中间人攻击

DOI:
10.1093/comjnl/bxac007
复制
发表时间:
2023
期刊:
The Computer Journal
影响因子:
--
通讯作者:
Jie Chen
Jie Chen
中科院分区:
其他
文献类型:
--
作者:
Xiaoli Dong;Yongzhuang Wei;Wen Gao;Jie Chen

文献摘要

相似文献

Fox分组密码采用Lai-Massey方案设计,其中轮函数采用替换-置换-替换结构。中间相遇(MITM)攻击是分组密码安全性最重要的问题之一,它由构造区分符的预计算阶段和密钥恢复的在线阶段组成。本文研究了针对FOX的MITM攻击。给出了5轮FOX64、7轮FOX64-256和5轮FOX128在使用截断微分特征的微分枚举法时的MITM判别器。在此基础上,利用状态测试和状态搜索技术,对7轮FOX64、11轮FOX64-256和7轮FOX128进行了密钥恢复攻击。结果表明,对11轮FOX64-256的攻击是首次提出的,对7轮FOX64和7轮FOX128的攻击可以改进,与已知的攻击相比,具有更低的时间和内存复杂度。
FOX block cipher was designed with a Lai–Massey scheme, in which the round function uses the Substitution-Permutation-Substitution structure. A meet-in-the-middle (MITM) attack is one of the most important issues for the security of the block cipher, which consists of a precomputation phase for constructing a distinguisher and an online phase for key recovery. This paper studies the MITM attacks against FOX. The first MITM distinguishers of 5-round FOX64, 7-round FOX64-256 and 5-round FOX128 are presented when using the differential enumeration technique with truncated differential characteristics. Then, based on these distinguishers, the attacks for key recovery on 7-round FOX64, 11-round FOX64-256 and 7-round FOX128 are presented with the state-test and state-search techniques. It is shown that the attack on 11-round FOX64-256 is proposed for the first time; attacks on 7-round FOX64 and 7-round FOX128 can be improved with lower time and memory complexities compared with the currently known attacks.