1. 信息工程大学,河南,郑州,450001
2. 数学工程与先进计算国家重点实验室,河南,郑州,450001
5. 上海交通大学计算机科学与工程系,上海,200240
网络出版:2017-04-25,
纸质出版:2017
移动端阅览
贾平, 徐洪, 来学嘉. LBlock-s算法的不可能差分分析[J]. 电子学报, 2017,45(4):966-973.
JIA Ping, XU Hong, LAI Xue-jia. Impossible Differential Cryptanalysis of Reduced-Round LBlock-s[J]. Acta Electronica Sinica, 2017, 45(4): 966-973.
贾平, 徐洪, 来学嘉. LBlock-s算法的不可能差分分析[J]. 电子学报, 2017,45(4):966-973. DOI: 10.3969/j.issn.0372-2112.2017.04.028.
JIA Ping, XU Hong, LAI Xue-jia. Impossible Differential Cryptanalysis of Reduced-Round LBlock-s[J]. Acta Electronica Sinica, 2017, 45(4): 966-973. DOI: 10.3969/j.issn.0372-2112.2017.04.028.
LBlock-s算法是CAESAR竞赛候选认证加密算法LAC中的主体算法,算法结构与LBlock算法基本一致,只是密钥扩展算法采用了扩散效果更好的增强版设计.利用新密钥扩展算法中仍然存在的子密钥间的迭代关系,通过选择合适的14轮不可能差分特征,我们给出了对21轮LBlock-s算法的不可能差分分析.攻击需要猜测的子密钥比特数为72比特,需要的数据量为2
63
个选择明文,时间复杂度约为2
67.61
次21轮加密.利用部分匹配技术,我们也给出了直到23轮LBlock-s算法低于密钥穷举量的不可能差分分析结果.这些研究可以为LAC算法的整体分析提供参考依据.
LBlock-s is the kernel block cipher of the authentication encryption algorithm LAC submitted to CAESAR competition.The general structure of LBlock-s is almost the same as that of LBlock
but LBlock-s adopts an improved key schedule algorithm with better diffusion property.Using the shifting relation of subkeys derived by the key schedule algorithm
an impossible differential cryptanalysis on 21-round LBlock-s was presented based on a 14-round impossible differential.The time and data complexities are 2
67.61
21-round encryptions and 2
63
chosen plaintexts respectively
and the number of subkey bits needed to be guessed is 72.Using partial-matching method
an impossible differential cryptanalysis on
LBlock-s up to 23-round was also presented with time complexity less than exhaustion of all key bits.This work is useful for the security analysis of LAC algorithm.
0
浏览量
488
下载量
1
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621