Related-Cipher Attack on Salsa20

Related-Cipher Attack on Salsa20
复制标题

DOI:
10.1109/iccis.2012.217
复制
发表时间:
2012-08
期刊:
2012 Fourth International Conference on Computational and Information Sciences
影响因子:
--
通讯作者:
Zeng-yu Shao;L. Ding
Zeng-yu Shao;L. Ding
中科院分区:
其他
文献类型:
--
作者:
Zeng-yu Shao;L. Ding

文献摘要

被引文献

相似文献

Salsa 20由丹尼尔伯恩斯坦提出,是eSTREAM项目的决赛选手之一。相关密码攻击是由吴红军于2002年提出的,并应用于分组密码。相关的密码可以看作是具有相同轮函数但轮数不同的密码。目前还没有相关的密码攻击应用于Salsa 20流密码。针对流密码Salsa 20采用灵活的轮数(Salsa 20的减轮版本),且其密钥调度与轮数无关的特点,提出了一种相关密码攻击方法.如果在Salsa 20/12和Salsa 20/8中使用一个密钥来加密同一消息,我们可以恢复256位的密钥,计算复杂度约为2224。结果表明,相关密码攻击同样可以应用于流密码。
Salsa20 was proposed by Daniel Bernstein and is one of the finalists of eSTREAM project. Related-cipher attack was introduced by Hongjun Wu in 2002 and applied to block ciphers. The related ciphers can be considered as ciphers with the same round function, but with different round numbers. There has not been any related-cipher attack applied to Salsa20 stream cipher. In this paper, we apply related-cipher attack on stream cipher Salsa20, since Salsa20 uses flexible rounds (reduced-round versions of Salsa20) and the key schedule of Salsa20 is independent of the number of rounds. If a secret key is used in Salsa20/12 and Salsa20/8 to encrypt the same message, we can recover the 256-bit secret key with computational complexity of about 2224. The result shows that related-cipher attack may be also applied to stream ciphers.