Cryptanalysis of reduced versions of the Camellia block cipher

Cryptanalysis of reduced versions of the Camellia block cipher
复制标题

DOI:
10.1049/iet-ifs.2011.0342
复制
发表时间:
2012-09
期刊:
IET Inf. Secur.
影响因子:
--
通讯作者:
Jiqiang Lu;Yongzhuang Wei;Pierre-Alain Fouque;Jongsung Kim
Jiqiang Lu;Yongzhuang Wei;Pierre-Alain Fouque;Jongsung Kim
中科院分区:
其他
文献类型:
--
作者:
Jiqiang Lu;Yongzhuang Wei;Pierre-Alain Fouque;Jongsung Kim

文献摘要

被引文献

相似文献

Camellia块密码具有128位块长度,用户密钥128、192或256位长,并且对于128位密钥总共18轮,对于192或256位密钥总共24轮。它是一种日本电子政务密码,欧洲新欧洲签名、完整性和加密方案(NESSIE)选择的密码和ISO国际标准。在这项研究中,作者描述了用于选择明文或密文的方法中的一个缺陷,并给出了两种可能的方法来纠正它们。最后,通过利用早期中止技术和对Camellia密钥调度的一些观察,作者提出了对FL/FL-1函数在128个密钥位下的10轮Camellia,FL/FL-1函数在192个密钥位下的11轮Camellia,没有FL/FL-1的14轮Camellia在192个密钥位下运行,没有FL/FL-1的16轮Camellia在256个密钥位下运行。
The Camellia block cipher has a 128-bit block length, a user key 128, 192 or 256 bits long and a total of 18 rounds for a 128-bit key and 24 rounds for a 192 or 256-bit key. It is a Japanese CRYPTREC-recommended e-government cipher, a European new European schemes for signatures, integrity and encryption (NESSIE) selected cipher and an ISO international standard. In this study, the authors describe a flaw in the approach used to choose plaintexts or ciphertexts in certain previously published square-like cryptanalytic results for Camellia and give two possible approaches to correct them. Finally, by taking advantage of the early abort technique and a few observations on the key schedule of Camellia, the authors present impossible differential attacks on 10-round Camellia with the FL/FL−1 functions under 128 key bits, 11-round Camellia with the FL/FL−1 functions under 192 key bits, 14-round Camellia without the FL/FL−1 functions under 192 key bits and 16-round Camellia without the FL/FL−1 functions under 256 key bits.