首页 | 本学科首页   官方微博 | 高级检索  
     

Impossible differential cryptanalysis of advanced encryption standard
摘    要:Impossible differential cryptanalysis is a method recovering secret key, which gets rid of the keys that satisfy impossible differential relations. This paper concentrates on the impossible differential cryptanalysis of Advanced Encryption Standard (AES) and presents two methods for impossible differential cryptanalysis of 7-round AES-192 and 8-round AES-256 combined with time-memory trade-off by exploiting weaknesses in their key schedule. This attack on the reduced to 7-round AES-192 requires about 294.5 chosen plaintexts, demands 2129 words of memory, and performs 2157 7-round AES-192 encryptions. Furthermore, this attack on the reduced to 8-round AES-256 requires about 2101 chosen plaintexts, demands 2201 words of memory, and performs 2228 8-round AES-256 encryptions.

收稿时间:2006-07-12
修稿时间:2007-09-30

Impossible differential cryptanalysis of Advanced Encryption Standard
Chen Jie,Hu YuPu,Zhang YueYu. Impossible differential cryptanalysis of Advanced Encryption Standard[J]. Science in China(Information Sciences), 2007, 50(3): 342-350. DOI: 10.1007/s11432-007-0035-4
Authors:Chen Jie  Hu YuPu  Zhang YueYu
Affiliation:Key Laboratory of Computer Networks & Information Security, Ministry of Education, Xidian University,Xi'an 710071, China
Abstract:Impossible differential cryptanalysis is a method recovering secret key, which gets rid of the keys that satisfy impossible differential relations. This paper concentrates on the impossible differential cryptanalysis of Advanced Encryption Standard (AES) and presents two methods for impossible differential cryptanalysis of 7-round AES-192 and 8-round AES-256 combined with time-memory trade-off by exploiting weaknesses in their key schedule. This attack on the reduced to 7-round AES-192 requires about 294.5 chosen plaintexts, demands 2129 words of memory, and performs 2157 7-round AES-192 encryptions. Furthermore, this attack on the reduced to 8-round AES-256 requires about 2101 chosen plaintexts, demands 2201 words of memory, and performs 2228 8-round AES-256 encryptions.
Keywords:block cipher  impossible differential cryptanatysis  advanced encryption standard  cryptanalysis
本文献已被 万方数据 SpringerLink 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号