On the Boomerang Uniformity of Cryptographic Sboxes

On the Boomerang Uniformity of Cryptographic Sboxes
复制标题

DOI:
10.13154/tosc.v2018.i3.290-310
复制
发表时间:
2018-01-01
影响因子:
3.5
通讯作者:
Canteaut, Anne
Canteaut, Anne
中科院分区:
其他
文献类型:
--
作者:
Boura, Christina;Canteaut, Anne

文献摘要

被引文献

相似文献

回旋镖攻击是针对分组密码的一种密码分析技术,它结合了密码上下部分的两个差分。这两个差异之间的依赖关系高度影响了攻击及其所有变体的复杂性。最近,Cid等人在Eurocrypt'18上介绍了一种新工具,称为Boomerang Connectivity Table(BCT),它可以通过在一个表中存储和统一密码Sbox的不同切换概率来简化这种复杂性分析。在这篇开创性的论文中,简要分析了这些表的属性,并提出了一些悬而未决的问题。它被问到,特别是S盒是否存在最佳的BCT甚至尺寸,其中最佳的意思是,在BCT的最大值等于最低的已知差分均匀性。当维数是偶数并且不同于6时,这样的最优S盒对应于置换,使得它们的DDT和它们的BCT中的最大值等于4(除非存在这样的维数的APN置换)。在这项工作中,我们提供了一个更深入的分析回飞棒连接表,通过研究更密切的差异4-均匀Sboxes。我们首先完全表征所有差分4-均匀排列的4位的BCT,然后研究这些对象的一些加密相关的家庭的Sboxes,作为反函数和二次排列。这两个家庭为我们提供了第一个例子的差分4均匀Sboxes最佳对回旋镖攻击的偶数个变量,回答了上述开放的问题。
The boomerang attack is a cryptanalysis technique against block ciphers which combines two differentials for the upper part and the lower part of the cipher. The dependency between these two differentials then highly affects the complexity of the attack and all its variants. Recently, Cid et al. introduced at Eurocrypt'18 a new tool, called the Boomerang Connectivity Table (BCT) that permits to simplify this complexity analysis, by storing and unifying the different switching probabilities of the cipher's Sbox in one table. In this seminal paper a brief analysis of the properties of these tables is provided and some open questions are raised. It is being asked in particular whether Sboxes with optimal BCTs exist for even dimensions, where optimal means that the maximal value in the BCT equals the lowest known differential uniformity. When the dimension is even and differs from 6, such optimal Sboxes correspond to permutations such that the maximal value in their DDT and in their BCT equals 4 (unless APN permutations for such dimensions exist). We provide in this work a more in-depth analysis of boomerang connectivity tables, by studying more closely differentially 4-uniform Sboxes. We first completely characterize the BCT of all differentially 4-uniform permutations of 4 bits and then study these objects for some cryptographically relevant families of Sboxes, as the inverse function and quadratic permutations. These two families provide us with the first examples of differentially 4-uniform Sboxes optimal against boomerang attacks for an even number of variables, answering the above open question.