Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers

被引:1
|
作者
Cao, Wenqin [1 ,2 ,3 ]
Zhang, Wentao [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur, 89 Minzhuang Rd, Beijing 100093, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, 19 Yuquan Rd, Beijing 100049, Peoples R China
[3] Shandong Univ Technol, Sch Math & Stat, 266Xincunxi Rd, Zibo 255000, Shandong, Peoples R China
基金
中国国家自然科学基金;
关键词
Key-alternating cipher; Key difference invariant bias; Multidimensional linear cryptanalysis; LBlock; TWINE; ATTACK;
D O I
10.1186/s42400-021-00096-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
For block ciphers, Bogdanov et al. found that there are some linear approximations satisfying that their biases are deterministically invariant under key difference. This property is called key difference invariant bias. Based on this property, Bogdanov et al. proposed a related-key statistical distinguisher and turned it into key-recovery attacks on LBlock and TWINE-128. In this paper, we propose a new related-key model by combining multidimensional linear cryptanalysis with key difference invariant bias. The main theoretical advantage is that our new model does not depend on statistical independence of linear approximations. We demonstrate our cryptanalysis technique by performing key recovery attacks on LBlock and TWINE-128. By using the relations of the involved round keys to reduce the number of guessed subkey bits. Moreover, the partial-compression technique is used to reduce the time complexity. We can recover the master key of LBlock up to 25 rounds with about 2(60.4) distinct known plaintexts, 2(78.85) time complexity and 2(61) bytes of memory requirements. Our attack can recover the master key of TWINE-128 up to 28 rounds with about 2(61.5) distinct known plaintexts, 2(126.15) time complexity and 2(61) bytes of memory requirements. The results are the currently best ones on cryptanalysis of LBlock and TWINE-128.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers
    Wenqin Cao
    Wentao Zhang
    Cybersecurity, 4
  • [2] Key Difference Invariant Bias in Block Ciphers
    Bogdanov, Andrey
    Boura, Christina
    Rijmen, Vincent
    Wang, Meiqin
    Wen, Long
    Zhao, Jingyuan
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2013, PT I, 2013, 8269 : 357 - 376
  • [3] Multidimensional Linear Cryptanalysis of Feistel Ciphers
    Ozdemir, Betuel Askin
    Beyne, Tim
    Rijmen, Vincent
    IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY, 2023, 2023 (04) : 1 - 27
  • [4] POSTER: Generic Multidimensional Linear Cryptanalysis of Feistel Ciphers
    Ozdemir, Betul Askin
    Beyne, Tim
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3621 - 3623
  • [5] Linear hulls with correlation zero and linear cryptanalysis of block ciphers
    Andrey Bogdanov
    Vincent Rijmen
    Designs, Codes and Cryptography, 2014, 70 : 369 - 383
  • [6] Linear hulls with correlation zero and linear cryptanalysis of block ciphers
    Bogdanov, Andrey
    Rijmen, Vincent
    DESIGNS CODES AND CRYPTOGRAPHY, 2014, 70 (03) : 369 - 383
  • [7] Methods for linear and differential cryptanalysis of elastic block ciphers
    Cook, Debra L.
    Yung, Moti
    Keromytis, Angelos D.
    INFORMATION SECURITY AND PRIVACY, 2008, 5107 : 187 - +
  • [8] Utilizing FWT in linear cryptanalysis of block ciphers with various structures
    Lv, Yin
    Shi, Danping
    Hu, Lei
    Guo, Yi
    DESIGNS CODES AND CRYPTOGRAPHY, 2024, 92 (11) : 3813 - 3842
  • [9] An application of genetic algorithm to cryptanalysis of block ciphers by partitioning the key space
    Borges-Trenard, Miguel A.
    Borges-Quintana, Mijail
    Monier-Columbie, Lazaro
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2022, 25 (02): : 325 - 334
  • [10] On linear cryptanalysis of MBAL Ciphers
    Kobayashi, K
    Aoki, K
    ELECTRONICS AND COMMUNICATIONS IN JAPAN PART III-FUNDAMENTAL ELECTRONIC SCIENCE, 1999, 82 (10): : 1 - 8