Truncated differential cryptanalysis of five rounds of Salsa20

Truncated differential cryptanalysis of five rounds of Salsa20
复制标题

DOI:
--
复制
发表时间:
2005
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Paul Crowley
Paul Crowley
中科院分区:
其他
文献类型:
--
作者:
Paul Crowley

文献摘要

被引文献

相似文献

我们对Salsa20的攻击减少到其二十回合中的五回合。这可能是为了方便起见的宽度,我们在这里回顾了salsa20-w/r的参数化家族,其中w salsa20 salsa20 salsa20-32/20是z/2wz的​​一个元素。通常的方式以及单词映射到字节的位置,使用一个小映射,我们在四元素的列列上定义了一个单词矢量:SA((y0 y1 y2 y3))=(y1⊕(y0) + y3)≪ a)y2 y3 Y0)并在相同的相同上构建该徒地图四次:Q =S18◦S13◦S9◦S7(请注意,订阅中给出的常数适用于W = 32;可用于其他W的不同常数可用于其他w )并用一行和列旋转以获取此列表上的这一射击图:q'(m)=m1,1m1,2 m1,2 Q1 m2,1平方米2,1平方米2,2平方米2,3 Q2 M3,1 M3,2 M3,3 Q3 M0,1 M0,2 M0,3 Q0∗ paul@ciphergoth.org。
We present an attack on Salsa20 reduced to five of its twenty rounds. This attack uses many clusters of truncated differentials and requires 2 work and 2 plaintexts. 1 Definition of Salsa20 Salsa20 [1] is a candidate in the eSTREAM project to identify new stream ciphers that might be suitable for widespread adoption. For convenience, we recap here the parameterized family of variants Salsa20-w/r, with w the word size and r the number of rounds; Salsa20 itself is Salsa20-32/20. A word is an element of Z/2wZ. We omit the precise definitions of word-oriented operations here for brevity; addition (+), XOR (⊕) and rotation (≪) are defined in the usual way, and where words are mapped to bytes, a little-endian mapping is used. We define a bijective map S on four-element column vectors of words: Sa(( y0 y1 y2 y3 ) ) = ( y1 ⊕ ((y0 + y3) ≪ a) y2 y3 y0 ) and compose it four times to build this bijective map on the same: Q = S18 ◦ S13 ◦ S9 ◦ S7 (note that the constants given in the subscripts are appropriate for w = 32; different constants might be used for a different w) and compose it with a row and column rotate to get this bijective map on matrices: Q′(m) =  m1,1 m1,2 m1,3 q1 m2,1 m2,2 m2,3 q2 m3,1 m3,2 m3,3 q3 m0,1 m0,2 m0,3 q0  ∗paul@ciphergoth.org. Work sponsored by LShift Ltd, www.lshift.net