Improved impossible differential cryptanalysis of large-block Rijndael

Improved impossible differential cryptanalysis of large-block Rijndael
复制标题

DOI:
10.1007/s11432-017-9365-4
复制
发表时间:
2018-07
期刊:
Science China Information Sciences
影响因子:
--
通讯作者:
Ya Liu;Yifan Shi;Dawu Gu;Bo Dai;Fengyu Zhao;Wei Li;Zhiqiang Liu;Zhiqiang Zeng
Ya Liu;Yifan Shi;Dawu Gu;Bo Dai;Fengyu Zhao;Wei Li;Zhiqiang Liu;Zhiqiang Zeng
中科院分区:
其他
文献类型:
--
作者:
Ya Liu;Yifan Shi;Dawu Gu;Bo Dai;Fengyu Zhao;Wei Li;Zhiqiang Liu;Zhiqiang Zeng

文献摘要

相似文献

Rijndael是一种用于AES开发过程的替换置换网络(SPN)分组密码。其块大小和密钥大小以32位为步长从128位到256位不等,可由Rijndael-b-k表示,其中Bandk分别是块大小和密钥大小。其中Rijndael-128-128/192/256,即AES,已经被很多研究人员研究过,其他大块版本Rijndael的安全性被利用较少。然而,随着量子计算机的快速发展,分组密码的大块版本越来越受到人们的关注。针对10轮Rijndael-256、10轮Rijndael-224-256和9轮Rijndael-224-224,利用预计算表、密钥调度冗余和多重不可能差分提出了改进的不可能差分攻击。对于10轮Rijndael-256-256,攻击的数据、时间和存储复杂度分别约为2244.4选择明文、2240.1加密和2181.4块。对于10轮Rijndael-224-256,攻击的数据、时间和存储复杂度分别约为2214.4个选择明文、2241.3个加密和2183.4个块。对于9轮Rijndael-224-224,攻击的数据、时间和存储复杂度分别约为2214.4个选择明文、2113.4个加密和287.4个块,或2206.6个选择明文、2153.6个加密和2111.6个块。据我们所知,我们目前在Rijndael-256-256和Rijndael-224-224/256上的结果是最好的。
Rijndael is a substitution-permutation network (SPN) block cipher for the AES development process. Its block and key sizes range from 128 to 256 bits in steps of 32 bits, which can be denoted by Rijndael-b-k, wherebandkare the block and key sizes, respectively. Among them, Rijndael-128-128/192/256, that is, AES, has been studied by many researchers, and the security of other large-block versions of Rijndael has been exploited less frequently. However, more attention has been paid to large-block versions of block ciphers with the fast development of quantum computers. In this paper, we propose improved impossible differential attacks on 10-round Rijndael-256-256, 10-round Rijndael-224-256, and 9-round Rijndael-224-224 using precomputation tables, redundancies of key schedules, and multiple impossible differentials. For 10-round Rijndael-256-256, the data, time, and memory complexities of our attack were approximately 2244.4chosen plaintexts, 2240.1encryptions, and 2181.4blocks, respectively. For 10-round Rijndael-224-256, the data, time, and memory complexities of our attack were approximately 2214.4chosen plaintexts, 2241.3encryptions, and 2183.4blocks, respectively. For 9-round Rijndael-224-224, the data, time, and memory complexities of our attack are approximately 2214.4chosen plaintexts, 2113.4encryptions, and 287.4blocks, respectively, or 2206.6chosen plaintexts, 2153.6encryptions, and 2111.6blocks, respectively. To the best of our knowledge, our results are currently the best on Rijndael-256-256 and Rijndael-224-224/256.