首页> 外文会议>International conference on cryptology in India >Counting Active S-Boxes is not Enough
【24h】

Counting Active S-Boxes is not Enough

机译:计数有源S盒是不够的

获取原文

摘要

Inspired by the works of Nyberg and Knudsen, the wide trail strategy suggests to ensure that the number of active S-boxes in a differential characteristic or a linear approximation is sufficiently high, thus, offering security against differential and linear attacks. Many cipher designers are relying on this strategy, and most new designs include analysis based on counting the number of active S-boxes. Unfortunately, this analysis is not always accurate and needs to be performed in a very delicate manner. To counter the common approach, we give an example of a 4-round Feistel construction with a very large number of active S-boxes that is expected to resist differential and linear cryptanalysis. However, we show that S-box counting arguments are insufficient in cases where one can find many differential characteristics with the same input and output difference. Namely, we show for a "prov-ably" secure 128-bit block, 4-round Feistel with at least 36 active AES S-boxes, that one can construct differential characteristics with probability 2~(-118) much higher than the bound of 2~(-216). Even if we compare this 4-round Feistel construction to a random permutation we obtain a 10x factor in the probability of the characteristic.
机译:灵感来自Nyberg和Knudsen的作品,宽阔的轨迹策略表明,确保差分特性或线性近似的有源S箱的数量足够高,因此提供了针对差分和线性攻击的安全性。许多密码设计人员依赖于此策略,大多数新设计包括基于计数有源S框的数量的分析。不幸的是,这种分析并不总是准确,并且需要以非常细腻的方式进行。为了抵消共同的方法,我们举例说明了一个具有非常大量的活动S箱的4轮Feistel结构的例子,这些箱预计将抵抗差分和线性密码分析。但是,我们表明,如果可以找到具有相同输入和输出差异的许多差分特性的情况下,S盒计数参数不足。即,我们展示了“PEP-ABEBLE”安全的128位块,4轮FEISTEL,至少具有36个有源AES S箱,即一个可以构造具有高于界限的概率2〜(-118)的差分特性2〜(-216)。即使我们将这种4轮Feistel结构与随机排列进行比较,我们也获得了特征概率的10倍因素。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号