首页 | 本学科首页   官方微博 | 高级检索  
     

概率积分密码分析
引用本文:李晓千,吴文玲,李宝,于晓丽.概率积分密码分析[J].计算机学报,2012,35(9):1897-1905.
作者姓名:李晓千  吴文玲  李宝  于晓丽
作者单位:1. 中国科学院信息工程研究所 北京100093
2. 中国科学院软件研究所 北京 100190
基金项目:国家自然科学基金,中国科学院战略性先导专项基金
摘    要:在传统的积分密码分析中,积分区分器都是以概率1成立的.虽然Knudsen等学者提到过:“就像差分一样,积分也可以是概率的”,但是,没有文献报道过进一步的研究.文中对此问题进行了探讨,提出了概率积分密码分析方法,并从理论和实验两方面验证了概率积分分析方法的有效性.对于采用S盒设计的分组密码,文中证明了如果S盒的差分均匀性越接近随机概率,则分组密码抵抗概率积分密码分析的能力就越强.同时,文中指出高阶积分分析的某些技巧对于概率积分分析是行不通的,主要原因是随着求和变量个数的增加,积分特征概率趋近于随机概率.最后,文中通过对AES和LBlock这两个算法的概率积分分析实例,说明目前广泛使用的分组密码算法对于概率积分密码分析方法都是免疫的.

关 键 词:积分密码分析  差分密码分析  概率积分密码分析  轻量级密码  AES  LBlock

Probabilistic Integral Cryptanalysis
LI Xiao-Qian , WU Wen-Ling , LI Bao , YU Xiao-Li.Probabilistic Integral Cryptanalysis[J].Chinese Journal of Computers,2012,35(9):1897-1905.
Authors:LI Xiao-Qian  WU Wen-Ling  LI Bao  YU Xiao-Li
Affiliation:1)(Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093)2)(Institute of Software,Chinese Academy of Sciences,Beijing 100190)
Abstract:In traditional integral cryptanalysis,the integral distinguisher was with probability 1.Knudsen once mentioned: "Integrals can be probabilistic just like differentials",but there was no further research afterwards.In this paper,we study deeply into this problem.Firstly,we introduce the method of Probabilistic Integral Cryptanalysis,and then we testify the validity of this method both in theory and experiment.For block cipher which contains S-boxes,it is proved that the closer the differential uniformity of S-boxes gets to random probability,the stronger the resistance of the block cipher to probabilistic integral cryptanalysis is.Finally,we point out that the techniques of higher order differential cryptanalysis do not work in probabilistic integral cryptanalysis,for the reason that the probability of integral characteristic regresses toward the random probability with increment of the number of sum variables.Furthermore,after the experimental probabilistic integral cryptanalysis of two block ciphers LBlock and AES,we come to a conclusion that most of existing modern block ciphers is immune to probabilistic integral cryptanalysis.
Keywords:integral cryptanalysis  differential cryptanalysis  probabilistic integral cryptanalysis  lightweight block cipher  AES  LBlock
本文献已被 CNKI 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号