New Attacks on LowMC Instances with a Single Plaintext/Ciphertext Pair

被引:10
作者
Banik, Subhadeep [1 ]
Barooti, Khashayar [1 ]
Vaudenay, Serge [1 ]
Yan, Hailun [1 ]
机构
[1] Ecole Polytech Fed Lausanne, LASEC, Lausanne, Switzerland
来源
ADVANCES IN CRYPTOLOGY - ASIACRYPT 2021, PT I | 2021年 / 13090卷
基金
瑞士国家科学基金会;
关键词
CRYPTANALYSIS;
D O I
10.1007/978-3-030-92062-3_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cryptanalysis of the LowMC block cipher when the attacker has access to a single known plaintext/ciphertext pair is a mathematically challenging problem. This is because the attacker is unable to employ most of the standard techniques in symmetric cryptography like linear and differential cryptanalysis. This scenario is particularly relevant while arguing the security of the PICNIC digital signature scheme in which the plaintext/ciphertext pair generated by the LowMC block cipher serves as the public (verification) key and the corresponding LowMC encryption key also serves as the secret (signing) key of the signature scheme. In the paper by Banik et al. (IACR ToSC 2020:4), the authors used a linearization technique of the LowMC S-box to mount attacks on some instances of the block cipher. In this paper, we first make a more precise complexity analysis of the linearization attack. Then, we show how to perform a 2-stage MITM attack on LowMC. The first stage reduces the key candidates corresponding to a fraction of key bits of the master key. The second MITM stage between this reduced candidate set and the remaining fraction of key bits successfully recovers the master key. We show that the combined computational complexity of both these stages is significantly lower than those reported in the ToSC paper by Banik et al.
引用
收藏
页码:303 / 331
页数:29
相关论文
共 13 条
  • [1] Ciphers for MPC and FHE
    Albrecht, Martin R.
    Rechberger, Christian
    Schneider, Thomas
    Tiessen, Tyge
    Zohner, Michael
    [J]. ADVANCES IN CRYPTOLOGY - EUROCRYPT 2015, PT I, 2015, 9056 : 430 - 454
  • [2] Cryptanalysis of LowMC instances using single plaintext/ciphertext pair
    Banik, Subhadeep
    Barooti, Khashayar
    Durak, F. Betul
    Vaudenay, Serge
    [J]. IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY, 2020, 2020 (04) : 130 - 146
  • [3] Bouillaguet C, 2010, LECT NOTES COMPUT SC, V6225, P203, DOI 10.1007/978-3-642-15031-9_14
  • [4] Dinur I., 2021, CRYPTANALYTIC APPL P
  • [5] Linear Equivalence of Block Ciphers with Partial Non-Linear Layers: Application to LowMC
    Dinur, Itai
    Kales, Daniel
    Promitzer, Angela
    Ramacher, Sebastian
    Rechberger, Christian
    [J]. ADVANCES IN CRYPTOLOGY - EUROCRYPT 2019, PT I, 2019, 11476 : 343 - 372
  • [6] Multi-target Attacks on the Picnic Signature Scheme and Related Protocols
    Dinur, Itai
    Nadler, Niv
    [J]. ADVANCES IN CRYPTOLOGY - EUROCRYPT 2019, PT III, 2019, 11478 : 699 - 727
  • [7] Optimized Interpolation Attacks on LowMC
    Dinur, Itai
    Liu, Yunwen
    Meier, Willi
    Wang, Qingju
    [J]. ADVANCES IN CRYPTOLOGY - ASIACRYPT 2015, PT II, 2015, 9453 : 535 - 560
  • [8] Dobraunig Christoph, 2016, Information Security and Cryptology - ICISC 2015. 18th International Conference. Revised Selected Papers: LNCS 9558, P87, DOI 10.1007/978-3-319-30840-1_6
  • [9] Grassi Lorenzo., 2020, Survey of Key-Recovery Attacks on LowMC in a Single Plaintext/Ciphertext Scenario
  • [10] Liu F., 2021, IACR CRYPTOL EPRINT, V255