首页> 外文期刊>IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences >Best Truncated and Impossible Differentials of Feistel Block Ciphers with S-D (Substitution and Diffusion) or D-S Round Functions
【24h】

Best Truncated and Impossible Differentials of Feistel Block Ciphers with S-D (Substitution and Diffusion) or D-S Round Functions

机译:具有S-D(替代和扩散)或D-S舍入函数的Feistel块密码的最佳截断和不可能的差分

获取原文
获取原文并翻译 | 示例
           

摘要

This paper describes truncated and impossible differentials of Feistel block ciphers with round functions of 2-layer SPN (Substitution and Permutation Network) transformation modules such as the 128-bit block cipher Camellia, which was proposed by NTT and Mitsubishi Electric Corporation. Our work improves on the best known truncated and impossible differentials, and has found a nontrivial 9-round truncated differential that: may lead to a possible attack against, a reduced-round version of Camellia without input/output whitening, FL or FL~(-1) (Camellia-NFL), in the chosen plain text scenario. Previously, only 6-round differentials were known that may suggest a possible attack of Camellia-NFL reduced to 8-rounds. We also show a nontrivial 7-round impossible differential, whereas only a 5-round impossible differential was previously known. We also consider the truncated differential of a reduced-round version of Camellia (Camellia-DS) whose round functions are composed of D-S (Diffusion and Substitution) transformation modules and without input/output whitening, FL or FL~(-1) (Camellia-DS-NFL), and show a nontrivial 9-round truncated differential, which may lead to a possible attack in the chosen plain text scenario. This truncated differential is effective for general Feistel structures with round functions composed of S-D (Substitution and Diffusion) or D-S transformation.
机译:本文介绍了具有2层SPN(替代和置换网络)转换模块的舍入功能的Feistel分组密码的截断和不可能的差分,例如NTT和三菱电机公司提出的128位分组密码Camellia。我们的工作改进了最著名的截断和不可能的差分,并发现了一个非平凡的9轮截断差分:可能导致对茶花的缩小回合版本的攻击,而没有输入/输出泛白,FL或FL〜( -1)(Camellia-NFL),在所选的纯文本方案中。以前,只有6轮的差异是已知的,这可能表明Camellia-NFL的进攻可能减少到8轮。我们还显示了一个非平凡的7轮不可能的差分,而以前只知道了5轮不可能的差分。我们还考虑了茶花(Camellia-DS)的简化舍入形式的截断差分,茶花的舍入功能由DS(扩散和替代)转换模块组成,并且没有输入/输出白化,FL或FL〜(-1)(Camellia -DS-NFL),并显示不平凡的9轮截断差分,这可能导致在选定的纯文本方案中可能的攻击。该截断的微分法对于具有由S-D(替代和扩散)或D-S变换组成的圆形函数的常规Feistel结构有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号