首页> 外文会议>Annual international conference on the theory and applications of cryptographic techniques >Provable Security Evaluation of Structures Against Impossible Differential and Zero Correlation Linear Cryptanalysis
【24h】

Provable Security Evaluation of Structures Against Impossible Differential and Zero Correlation Linear Cryptanalysis

机译:针对不可微分和零相关线性密码分析的结构的可行安全性评估

获取原文

摘要

Impossible differential and zero correlation linear cryptanalysis are two of the most important cryptanalytic vectors. To characterize the impossible differentials and zero correlation linear hulls which are independent of the choices of the non-linear components, Sun et al. proposed the structure deduced by a block cipher at CRYPTO 2015. Based on that, we concentrate in this paper on the security of the SPN structure and Feistel structure with SP-type round functions. Firstly, we prove that for an SPN structure, if α_1 → β_1 and α_2 → β_2 are possible differentials, α_1|α_2 → β_1|β_2 is also a possible differential, i.e., the OR "|" operation preserves differentials. Secondly, we show that for an SPN structure, there exists an r-round impossible differential if and only if there exists an r-round impossible differential α (→) β where the Hamming weights of both α and β are 1. Thus for an SPN structure operating on m bytes, the computation complexity for deciding whether there exists an impossible differential can be reduced from O(2~(2m)) to O(m~2). Thirdly, we associate a primitive index with the linear layers of SPN structures. Based on the matrices theory over integer rings, we prove that the length of impossible differentials of an SPN structure is upper bounded by the primitive index of the linear layers. As a result we show that, unless the details of the S-boxes are considered, there do not exist 5-round impossible differentials for the AES and ARIA. Lastly, based on the links between impossible differential and zero correlation linear hull, we projected these results on impossible differentials to zero correlation linear hulls. It is interesting to note some of our results also apply to the Feistel structures with SP-type round functions.
机译:不可能的差分和零相关线性密码分析是两个最重要的密码分析向量。为了表征不可能的微分和零相关线性船体,它们与非线性分量的选择无关,Sun等人。在CRYPTO 2015上,提出了由分组密码推导的结构。在此基础上,我们集中讨论SPN轮功能的SPN结构和Feistel结构的安全性。首先,我们证明对于SPN结构,如果α_1→β_1和α_2→β_2是可能的差分,则α_1|α_2→β_1|β_2也是可能的差分,即OR“ |”操作会保留差异。其次,我们表明对于SPN结构,当且仅当存在一个r圆不可能微分α(→)β且α和β的汉明权重均为1时,才存在r圆不可能微分。 SPN结构在m个字节上运行,可以将用于确定是否存在不可能的差分的计算复杂度从O(2〜(2m))降低到O(m〜2)。第三,我们将原始索引与SPN结构的线性层相关联。基于整数环上的矩阵理论,我们证明了SPN结构的不可能微分的长度是由线性层的原始索引来界定的。结果表明,除非考虑到S盒的细节,否则AES和ARIA不会存在5轮不可能的差异。最后,基于不可能微分和零相关线性船体之间的联系,我们将这些结果投影在不可能相关的零相关线性船体上。有趣的是,我们的一些结果也适用于带有SP型舍入函数的Feistel结构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号