首页> 外文会议>International Conference on Selected Areas in Cryptography >Towards Key-Dependent Integral and Impossible Differential Distinguishers on 5-Round AES
【24h】

Towards Key-Dependent Integral and Impossible Differential Distinguishers on 5-Round AES

机译:在5圆形的AES上朝向关键依赖的积分和不可能的差分区分器

获取原文

摘要

Reduced-round AES has been a popular underlying primitive to design new cryptographic schemes and thus its security including distinguishing properties deserves more attention. At Crypto'16, a key-dependent integral distinguisher on 5-round AES was put forward, which opened up a new direction to take more insights into the distinguishing properties of AES. After that, two key-dependent impossible differential (ID) distinguishers on 5-round AES were proposed at FSE'16 and CT-RSA'18, respectively. It is strange that the current key-dependent integral distinguisher requires significantly higher complexities than the key-dependent ID distinguishers, even though they are constructed with the same property of MixColumns (2~(128) 2~(98.2)). Proposers of the 5-round key-dependent distinguishers claimed that the corresponding integral and ID distinguishers can only work under chosen-ciphertext and chosen-plaintext settings, respectively, which is very different from the situations of traditional key-independent distinguishers. In this paper, we first construct a novel key-dependent integral distinguisher on 5-round AES with 2~(96) chosen plaintexts, which is much better than the previous key-dependent integral distinguisher that requires the full codebook proposed at Crypto'16. Secondly, We show that both distinguishers are valid under either chosen-plaintext setting or chosen-ciphertext setting, which is different from the claims of previous cryptanalysis. However, under different settings, complexities of key-dependent integral distinguishers are very different while those of the key-dependent ID distinguishers are almost the same. We analyze the reasons for it.
机译:减少AES是一个流行的基本原始,以设计新的加密方案,因此其安全性包括区分属性的安全性值得更加关注。在Crypto'16,提出了一个关键依赖的整体区分器,向前提出了一个新的方向,以便对AES的显着物质进行更多的洞察。之后,在FSE16和CT-RSA'18分别提出了两个关键依赖性不可能的差分(ID)在5圆形AES上进行区分。即使它们由MixColumns(2〜(128) 2〜(98.2)2〜(98.2)的相同属性构建,当前依赖于密钥依赖性积分区分器需要显着更高的复杂性。 5轮依赖键区分器的提议者声称相应的积分和ID区分器只能在选择密文和选择明文设置,分别,这是从传统的键无关的区分器的情况下非常不同的工作。在本文中,我们首先构造上5轮AES一种新颖的依赖键积分区分器2〜(96)选择明文,这是更好的比需要在Crypto'16提出的满码本以前依赖键积分区分器。其次,我们表明,两个区别在所选的明文设置或选择的密文设置中有效,这与先前密码分析的索赔不同。但是,在不同的设置下,关键依赖性积分器的复杂性非常不同,而关键依赖的ID区分器几乎是相同的。我们分析了它的原因。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号