Impossible differential cryptanalysis using matrix method

被引:35
作者
Kim, Jongsung [2 ]
Hong, Seokhie [1 ]
Lim, Jongin [1 ]
机构
[1] Korea Univ, CIST, Seoul, South Korea
[2] Kyungnam Univ, Div E Business, Masan, Kyungnam, South Korea
关键词
Cryptanalysis; Block ciphers; Impossible differential cryptanalysis; Matrix method; Feistel; Rijndael; Skipjack; SECURITY;
D O I
10.1016/j.disc.2009.10.019
中图分类号
O1 [数学];
学科分类号
0701 ; 070101 ;
摘要
The general strategy of impossible differential cryptanalysis is to first find impossible differentials and then exploit them for retrieving subkey material from the outer rounds of block ciphers. Thus, impossible differentials are one of the crucial factors to see how much the underlying block ciphers are resistant to impossible differential cryptanalysis. In this article, we introduce a widely applicable matrix method to find impossible differentials of block cipher structures whose round functions are bijective. Using this method, we find various impossible differentials of known block cipher structures: Nyberg's generalized Feistel network, a generalized CAST256-like structure, a generalized MARS-like structure, a generalized RC6-like structure, Rijndael structures and generalized Skipjack-like structures. We expect that the matrix method developed in this article will be useful for evaluating the security of block ciphers against impossible differential cryptanalysis, especially when one tries to design a block cipher with a secure structure. (C) 2009 Elsevier B.V. All rights reserved.
引用
收藏
页码:988 / 1002
页数:15
相关论文
共 18 条
[11]  
Knudsen L.R., 1998, DEAL 128 BIT BLOCK C
[12]  
LU J, 2009, LNCS, V5365, P279
[13]  
Matsui M., LNCS, V765, P386
[14]  
MATSUI M, 1996, LECT NOTES COMPUTER, V1039, P205
[15]  
Moriai S, 2000, LECT NOTES COMPUT SC, V1976, P289
[16]  
*NAT SEC SURV, 1998, SKIPJ KEA ALG SPEC V
[17]  
Sung JC, 2000, LECT NOTES COMPUT SC, V1976, P274
[18]   Decorrelation: A theory for block cipher security [J].
Vaudenay, S .
JOURNAL OF CRYPTOLOGY, 2003, 16 (04) :249-286