Improved meet-in-the-middle attacks on reduced-round Piccolo

Improved meet-in-the-middle attacks on reduced-round Piccolo
复制标题

DOI:
10.1007/s11432-016-9157-y
复制
发表时间:
2017-11
期刊:
Science China Information Sciences
影响因子:
--
通讯作者:
Ya Liu;Liang Cheng;Zhiqiang Liu;Wei Li;Qingju Wang;Dawu Gu
Ya Liu;Liang Cheng;Zhiqiang Liu;Wei Li;Qingju Wang;Dawu Gu
中科院分区:
其他
文献类型:
--
作者:
Ya Liu;Liang Cheng;Zhiqiang Liu;Wei Li;Qingju Wang;Dawu Gu

文献摘要

相似文献

Piccolo是一种轻量级分组密码,采用广义Feistel网络结构,有4个分支,每个分支长度为16位。密钥长度为80位或128位,分别用Piccolo-80和Piccolo-128表示。本文利用密钥调度和最大距离可分离矩阵的特性,对14轮无前后白化密钥的Piccolo-80和18轮带后白化密钥的Piccolo-128进行了中间相遇攻击。对于短笛-80,我们首先构建了一个5轮区分器。然后在开始和结束时分别加4轮和5轮。基于这个结构,我们从第5轮到第18轮对14发短笛-80进行了攻击。数据、时间和内存复杂度分别为252个选择的明文、267.44个加密和264.91个块。对于Piccolo-128,我们建立了一个7回合的区分器,从第4回合到第21回合攻击18回合的Piccolo-128。数据、时间和内存复杂度分别为252个选择的明文、2126.63个加密和2125.29个块。如果不考虑biclique密码分析的结果,这些是目前在Piccolo分组密码的简化版本上的最佳公开结果。
Piccolo is a lightweight block cipher that adopts a generalized Feistel network structure with 4 branches, each of which is 16 bit long. The key length is 80 or 128 bit, denoted by Piccolo-80 and Piccolo-128, respectively. In this paper, we mounted meet-in-the-middle attacks on 14-round Piccolo-80 without preand post-whitening keys and 18-round Piccolo-128 with post-whitening keys by exploiting the properties of the key schedule and Maximum Distance Separable (MDS) matrix. For Piccolo-80, we first constructed a 5-round distinguisher. Then 4 rounds and 5 rounds were appended at the beginning and at the end, respectively. Based on this structure, we mounted an attack on 14-round Piccolo-80 from the 5th round to the 18th round. The data, time, and memory complexities were 252chosen plaintexts, 267.44encryptions, and 264.91blocks, respectively. For Piccolo-128, we built a 7-round distinguisher to attack 18-round Piccolo-128 from the 4th round to the 21st round. The data, time, and memory complexities were 252chosen plaintexts, 2126.63encryptions, and 2125.29blocks, respectively. If not considering results on biclique cryptanalysis, these are currently the best public results on this reduced version of the Piccolo block cipher.