Utilizing FWT in linear cryptanalysis of block ciphers with various structures

被引:0
|
作者
Lv, Yin [1 ]
Shi, Danping [2 ,3 ]
Hu, Lei [2 ,3 ]
Guo, Yi [2 ,3 ]
机构
[1] South China Normal Univ, Sch Comp Sci, Guangzhou 510631, Peoples R China
[2] Chinese Acad Sci, Inst Informat Engn, Key Lab Cyberspace Secur Def, Beijing 100085, Peoples R China
[3] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100093, Peoples R China
基金
中国国家自然科学基金;
关键词
FWT; Linear cryptanalysis; Zero-correlation; KATAN; SPARX-128/128; ZERO;
D O I
10.1007/s10623-024-01458-y
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Linear cryptanalysis is one of the most classical cryptanalysis methods for block ciphers. Some critical techniques of the key-recovery phase are developed for enhancing linear cryptanalysis. Collard et al. improved the time complexity for last-round key-recovery attacks by using FWT. A generalized key-recovery algorithm for an arbitrary number of rounds with an associated time complexity formula is further provided by Fl & oacute;rez-Guti & eacute;rrez and Naya-Plasencia based on FWT in Eurocrypt 2020. However, the previous generalized algorithms are mainly applied to block ciphers with SPN structures, where the round-keys in the first and last round XORed to the state can be easily defined as outer keys. In Asiacrypt 2021, Leurent et al. applied the algorithm by Fl & oacute;rez-Guti & eacute;rrez et al. to Feistel structure ciphers. However, for other structures, such as NLFSR-based, the outer keys can not be directly deduced to utilize the previous algorithms. This paper extends the algorithm by Fl & oacute;rez-Guti & eacute;rrez et al. for more complicated structures, including but not limited to NLFSR-based, Feistel, ARX, and SPN. We also use the dependency relationships between ciphertext, plaintext and key information bits to eliminate the redundancy calculation and the improve analysis phase. We apply the algorithm with the improved analysis phase to KATAN (NLFSR-based) and SPARX (ARX). We obtain significantly improved results. The linear results we find for SPARX-128/128 beat other cryptanalytic techniques, becoming the best key recovery attacks on this cipher. The previous best linear attacks on KATAN32, KATAN48 and KATAN64 are improved by 9, 4, and 14 rounds, respectively.
引用
收藏
页码:3813 / 3842
页数:30
相关论文
共 50 条
  • [1] Linear hulls with correlation zero and linear cryptanalysis of block ciphers
    Andrey Bogdanov
    Vincent Rijmen
    Designs, Codes and Cryptography, 2014, 70 : 369 - 383
  • [2] Linear hulls with correlation zero and linear cryptanalysis of block ciphers
    Bogdanov, Andrey
    Rijmen, Vincent
    DESIGNS CODES AND CRYPTOGRAPHY, 2014, 70 (03) : 369 - 383
  • [3] Methods for linear and differential cryptanalysis of elastic block ciphers
    Cook, Debra L.
    Yung, Moti
    Keromytis, Angelos D.
    INFORMATION SECURITY AND PRIVACY, 2008, 5107 : 187 - +
  • [4] On linear cryptanalysis of MBAL Ciphers
    Kobayashi, K
    Aoki, K
    ELECTRONICS AND COMMUNICATIONS IN JAPAN PART III-FUNDAMENTAL ELECTRONIC SCIENCE, 1999, 82 (10): : 1 - 8
  • [5] On linear cryptanalysis of MBAL Ciphers
    Kobayashi, Kunio
    Aoki, Kazumaro
    Electronics and Communications in Japan, Part III: Fundamental Electronic Science (English translation of Denshi Tsushin Gakkai Ronbunshi), 1999, 82 (10): : 1 - 8
  • [6] On a structure of block ciphers with provable security against differential and linear cryptanalysis
    Matsui, M
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 1999, E82A (01) : 117 - 122
  • [7] Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers
    Cao, Wenqin
    Zhang, Wentao
    CYBERSECURITY, 2021, 4 (01)
  • [8] Provable security of block ciphers against linear cryptanalysis: a mission impossible?
    Piret, Gilles
    Standaert, Francois-Xavier
    DESIGNS CODES AND CRYPTOGRAPHY, 2009, 50 (03) : 325 - 338
  • [9] Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers
    Wenqin Cao
    Wentao Zhang
    Cybersecurity, 4
  • [10] Quantum Differential Cryptanalysis to the Block Ciphers
    Li, Hongwei
    Yang, Li
    APPLICATIONS AND TECHNIQUES IN INFORMATION SECURITY, ATIS 2015, 2015, 557 : 44 - 51