New Types of Cryptanalytic Attacks Using related Keys (Extended Abstract)

New Types of Cryptanalytic Attacks Using related Keys (Extended Abstract)
复制标题

DOI:
10.1007/3-540-48285-7_34
复制
发表时间:
1994-01
期刊:
--
影响因子:
--
通讯作者:
E. Biham
E. Biham
中科院分区:
其他
文献类型:
--
作者:
E. Biham

文献摘要

被引文献

相似文献

本文研究了密钥调度算法对分组密码强度的影响。我们证明了许多分组密码的密钥调度算法继承了密钥之间的明显关系,并利用这些密钥关系来攻击分组密码。描述了两种新的攻击类型:新的选择明文减少了穷举搜索攻击的复杂性(以及基于互补性质的更快的变体),以及新的低复杂性的选择密钥攻击。这些攻击与密码系统的轮数和F函数的细节无关,并且可能具有非常小的复杂性。这些攻击表明,密钥调度算法应该精心设计,其结构不应过于简单。这些攻击既适用于Loki的变体,也适用于Lucifer。DES不容易受到相关密钥的攻击,因为密钥调度算法中的移位模式在所有轮次中都不相同。
In this paper we study the influence of key-scheduling algorithms on the strength of blockciphers. We show that the key-scheduling algorithms of many blockciphers inherit obvious relationships between keys, and use these key relations to attack the blockciphers. Two new types of attacks are described: New chosen plaintext reductions of the complexity of exhaustive search attacks (and the faster variants based on complementation properties), and new low-complexity chosen key attacks. These attacks are independent of the number of rounds of the cryptosystems and of the details of theF-function and may have very small complexities. These attacks show that the key-scheduling algorithm should be carefully designed and that its structure should not be too simple. These attacks are applicable to both variants of LOKI and to Lucifer. DES is not vulnerable to the related keys attacks since the shift pattern in the key-scheduling algorithm is not the same in all the rounds.