Security Analysis of SKINNY under Related-Tweakey Settings

Security Analysis of SKINNY under Related-Tweakey Settings
复制标题

DOI:
10.13154/tosc.v2017.i3.37-72
复制
发表时间:
2017-09
期刊:
IACR Trans. Symmetric Cryptol.
影响因子:
--
通讯作者:
Guozhen Liu;Mohona Ghosh;Song Ling
Guozhen Liu;Mohona Ghosh;Song Ling
中科院分区:
其他
文献类型:
--
作者:
Guozhen Liu;Mohona Ghosh;Song Ling

文献摘要

被引文献

相似文献

在2016年的专利申请中,引入了一个新的可调整的轻量级分组密码家族- SKINNY。将SKINNY的变体表示为SKINNY-n-t,其中n表示块大小,t表示微调长度,设计指定t ∈ {n,2n,3 n}。在这项工作中,我们评估的安全性SKINNY对差分密码分析的相关调整模型。首先,我们研究了SKINNY的截断相关调整微分轨迹,并搜索了最长的不可能和矩形搜索器,其中在输入和输出中只有一个活动单元。根据所得到的攻击者,分别可以攻击SKINNY-n-n、SKINNY-n-2n和SKINNY-n-3 n的19、23和27轮。其次,研究了相关调整模型下SKINNY的实际微分路径,并采用基于混合线性规划的间接搜索方法,在一定轮数内搜索SKINNY-64的最优微分路径。结果表明,随着轮数的增加,最优差分轨迹的概率远低于SKINNY中活动Sbox下界的概率。
In CRYPTO’16, a new family of tweakable lightweight block ciphers - SKINNY was introduced. Denoting the variants of SKINNY as SKINNY-n-t, where n represents the block size and t represents the tweakey length, the design specifies t ∈ {n, 2n, 3n}. In this work, we evaluate the security of SKINNY against differential cryptanalysis in the related-tweakey model. First, we investigate truncated related-tweakey differential trails of SKINNY and search for the longest impossible and rectangle distinguishers where there is only one active cell in the input and the output. Based on the distinguishers obtained, 19, 23 and 27 rounds of SKINNY-n-n, SKINNY-n-2n and SKINNY-n-3n can be attacked respectively. Next, actual differential trails for SKINNY under related-tweakey model are explored and optimal differential trails of SKINNY-64 within certain number of rounds are searched with an indirect searching method based on Mixed-Integer Linear Programming. The results show a trend that as the number of rounds increases, the probability of optimal differential trails is much lower than the probability derived from the lower bounds of active Sboxes in SKINNY.