首页 | 本学科首页   官方微博 | 高级检索  
     

LBlock-s算法的不可能差分分析
引用本文:贾平,徐洪,来学嘉.LBlock-s算法的不可能差分分析[J].电子学报,2017,45(4):966-973.
作者姓名:贾平  徐洪  来学嘉
作者单位:1. 信息工程大学, 河南郑州 450001; 2. 数学工程与先进计算国家重点实验室, 河南郑州 450001; 3. 上海交通大学计算机科学与工程系, 上海 200240
基金项目:国家自然科学基金,国家863高技术研究发展计划
摘    要:LBlock-s算法是CAESAR竞赛候选认证加密算法LAC中的主体算法,算法结构与LBlock算法基本一致,只是密钥扩展算法采用了扩散效果更好的增强版设计.利用新密钥扩展算法中仍然存在的子密钥间的迭代关系,通过选择合适的14轮不可能差分特征,我们给出了对21轮LBlock-s算法的不可能差分分析.攻击需要猜测的子密钥比特数为72比特,需要的数据量为263个选择明文,时间复杂度约为267.61次21轮加密.利用部分匹配技术,我们也给出了直到23轮LBlock-s算法低于密钥穷举量的不可能差分分析结果.这些研究可以为LAC算法的整体分析提供参考依据.

关 键 词:LBlock算法  LBlock-s算法  密钥扩展算法  不可能差分分析  
收稿时间:2015-10-23

Impossible Differential Cryptanalysis of Reduced-Round LBlock-s
JIA Ping,XU Hong,LAI Xue-jia.Impossible Differential Cryptanalysis of Reduced-Round LBlock-s[J].Acta Electronica Sinica,2017,45(4):966-973.
Authors:JIA Ping  XU Hong  LAI Xue-jia
Affiliation:1. Information Engineering University, Zhengzhou, Henan 450001, China; 2. State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou, Henan 450001, China; 3. Department of Computer Science & Engineering, Shanghai Jiao Tong University, Shanghai 200240, China
Abstract:LBlock-s is the kernel block cipher of the authentication encryption algorithm LAC submitted to CAESAR competition.The general structure of LBlock-s is almost the same as that of LBlock,but LBlock-s adopts an improved key schedule algorithm with better diffusion property.Using the shifting relation of subkeys derived by the key schedule algorithm,an impossible differential cryptanalysis on 21-round LBlock-s was presented based on a 14-round impossible differential.The time and data complexities are 2.67.61 21-round encryptions and 2.63 chosen plaintexts respectively,and the number of subkey bits needed to be guessed is 72.Using partial-matching method,an impossible differential cryptanalysis on LBlock-s up to 23-round was also presented with time complexity less than exhaustion of all key bits.This work is useful for the security analysis of LAC algorithm.
Keywords:LBlock  LBlock-s  key schedule algorithm  impossible differential cryptanalysis
本文献已被 万方数据 等数据库收录!
点击此处可从《电子学报》浏览原始摘要信息
点击此处可从《电子学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号