Differential and Linear Cryptanalysis Using Mixed-Integer Linear Programming

Differential and Linear Cryptanalysis Using Mixed-Integer Linear Programming
复制标题

DOI:
10.1007/978-3-642-34704-7_5
复制
发表时间:
2011-11
影响因子:
--
通讯作者:
N. Mouha;Qingju Wang;Dawu Gu;B. Preneel
N. Mouha;Qingju Wang;Dawu Gu;B. Preneel
中科院分区:
综合性期刊3区
文献类型:
--
作者:
N. Mouha;Qingju Wang;Dawu Gu;B. Preneel

文献摘要

被引文献

相似文献

差分和线性密码分析是分析密钥原语的两种最有效的技术。因此,对于现代密码来说,抵抗这些攻击是一个强制性的设计标准。在本文中,我们提出了一种新的技术来证明对差分和线性密码分析的安全界限。我们使用混合整数线性规划(MILP),这是一种在商业和经济中经常使用的方法来解决优化问题。我们的技术大大减少了设计人员和密码分析人员的工作量,因为它只涉及写出输入到MILP求解器的简单方程。由于只需要很少的编程,因此大大减少了密码分析所花费的时间和人为错误的可能性。我们的方法被用来分析Enocoro-128 v2,一个由96轮组成的流密码。我们证明了38轮足以抵抗差分密码分析,61轮足以抵抗线性密码分析。我们还说明了我们的技术,通过计算AES的活动S盒的数量。
Differential and linear cryptanalysis are two of the most powerful techniques to analyze symmetric-key primitives. For modern ciphers, resistance against these attacks is therefore a mandatory design criterion. In this paper, we propose a novel technique to prove security bounds against both differential and linear cryptanalysis. We use mixed-integer linear programming (MILP), a method that is frequently used in business and economics to solve optimization problems. Our technique significantly reduces the workload of designers and cryptanalysts, because it only involves writing out simple equations that are input into an MILP solver. As very little programming is required, both the time spent on cryptanalysis and the possibility of human errors are greatly reduced. Our method is used to analyze Enocoro-128v2, a stream cipher that consists of 96 rounds. We prove that 38 rounds are sufficient for security against differential cryptanalysis, and 61 rounds for security against linear cryptanalysis. We also illustrate our technique by calculating the number of active S-boxes for AES.