Block Ciphers Sensitive to Gröbner Basis Attacks

Block Ciphers Sensitive to Gröbner Basis Attacks
复制标题

DOI:
10.1007/11605805_20
复制
发表时间:
2006-02
期刊:
--
影响因子:
--
通讯作者:
J. Buchmann;A. Pyshkin;R. Weinmann
J. Buchmann;A. Pyshkin;R. Weinmann
中科院分区:
其他
文献类型:
--
作者:
J. Buchmann;A. Pyshkin;R. Weinmann

文献摘要

被引文献

相似文献

We construct and analyze Feistel and SPN ciphers that have a sound design strategy against linear and differential attacks but for which the encryption process can be described by very simple polynomial equations. For a block and key size of 128 bits, we present ciphers for which practical Gröbner basis attacks can recover the full cipher key requiring only a minimal number of plaintext/ciphertext pairs. We show how Gröbner bases for a subset of these ciphers can be constructed with neglegible computational effort. This reduces the key–recovery problem to a Gröbner basis conversion problem. By bounding the running time of a Gröbner basis conversion algorithm, FGLM, we demonstrate the existence of block ciphers resistant against differential and linear cryptanalysis but vulnerable against Gröbner basis attacks.