A Guess-and-Determine Attack on Reduced-Round Khudra and Weak Keys of Full Cipher

A Guess-and-Determine Attack on Reduced-Round Khudra and Weak Keys of Full Cipher
复制标题

DOI:
--
复制
发表时间:
2015
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Mehmet Ozen;M. Coban;Ferhat Karakoç
Mehmet Ozen;M. Coban;Ferhat Karakoç
中科院分区:
其他
文献类型:
--
作者:
Mehmet Ozen;M. Coban;Ferhat Karakoç

文献摘要

被引文献

相似文献

Khudra是一个轻量级的分组密码,设计用于基于现场可编程门阵列(FPGA)的平台。该密码具有18轮广义2型Feistel结构,块大小为64位。密钥调度采用80位主密钥,并生成32位轮密钥,执行非常简单的操作。在这项工作中,我们分析了Khudra的安全性。我们首先证明了有效的轮密钥长度是16位。利用这一发现,我们改进了Youssef等人提出的14轮MITM攻击,将内存复杂度从2降低到2。此外,我们提出了一个新的猜测和确定型攻击14轮,只有2个已知的明文密文对需要安装在2个加密操作的时间复杂度的攻击。据我们所知,这是单密钥模型中在时间、内存和数据复杂度方面最好的攻击,其中数据复杂度等于最小理论数据要求。此外,我们提出了两个观察轮函数的差分概率和密码的对称结构。利用密码的对称结构,我们为全密码引入了两个弱密钥。
Khudra is a lightweight block cipher designed for Field Programmable Gate Array (FPGA) based platforms. The cipher has an 18-round generalized type-2 Feistel structure with 64-bit block size. The key schedule takes 80-bit master key and produces 32-bit round keys performing very simple operations. In this work, we analyze the security of Khudra. We first show that the effective round key length is 16-bit. By the help of this observation, we improve the 14-round MITM attack proposed by Youssef et al. by reducing the memory complexity from 2 to 2. Also, we propose a new guess-and-determine type attack on 14 rounds where only 2 known plaintext-ciphertext pairs are required to mount the attack in a time complexity of 2 encryption operations. To the best of our knowledge, this is the best attack in the single key model in terms of time, memory and data complexities where the data complexity is equal to the minimum theoretical data requirement. Moreover, we present two observations on differential probabilities of the round function and the symmetric structure of the cipher. We introduce 2 weak keys for the full cipher by exploiting the symmetric structure of the cipher.