节点文献

几类流密码分析技术研究

On Several Cryptanalytic Techniques of Stream Ciphers

【作者】 杨文峰

【导师】 胡予濮;

【作者基本信息】 西安电子科技大学 , 密码学, 2011, 博士

【摘要】 作为一种重要的密码体制,流密码在保密通信中有着广泛的应用.密码分析技术对流密码的设计有着不可替代的指导作用,也是密码学研究中的一个难点和热点问题.本文主要研究流密码分析技术的理论及其应用,得到的主要成果如下:(1)针对两类特殊的滤波生成器,即滤波函数为对称布尔函数时,提出了相应的代数攻击方法.不同于经典的代数攻击策略,该攻击方法主要是利用线性反馈移位寄存器和对称布尔函数的组合性质得到一个低次代数关系,从而使得攻击的复杂度与滤波函数的代数免疫度无关.攻击结果表明,线性移位寄存器与滤波函数的不恰当组合会使滤波生成器受到代数攻击的威胁.因此,在设计滤波生成器时,设计者不但要选择具有高代数免疫度的滤波函数,而且还必须合理选择线性移位寄存器和滤波函数的结合方式.(2)针对使用线性同步机制的同步流密码,当其组合函数为Maiorana–McFarland(M–M)函数时,综合利用线性同步机制和M–M函数的弱点,应用线性一致性测试方法,给出了一种同步攻击方法.攻击结果表明,在流密码设计中,不要单独使用M–M函数而应该跟其它的非线性函数结合起来使用.另外,尽管线性同步机制具有实现简单,运行高效等优点,但是在同步流密码设计中应精心设计以抵抗所提出的攻击.(3)通过分析流密码Grain的密钥流生成器的代数结构,发现了Grain密钥流生成器的三个设计弱点.尽管利用这三个设计弱点还不能针对Grain实施完整的密钥恢复攻击,但是据此提出了一种基于密钥流生成器中间状态的密钥恢复攻击.攻击结果表明, Grain密钥流生成器的设计还存在安全漏洞.更进一步,对Grain密钥流生成器的设计进行了改进.安全性分析表明改进设计能够抵抗所提出的密钥恢复攻击.(4)从代数攻击的角度对多路复合序列生成器进行了安全性分析.求出了复合器函数所有线性无关的最低次零化函数,并据此给出了多路复合序列生成器的一种代数攻击方法.跟已知的攻击方法相比,提出的代数攻击在某些情形下具有优势.

【Abstract】 As an important cryptographic primitive, stream ciphers have found widespreadapplications in secure communications. Cryptanalytic technology has been proven in-dispensable to the design of stream ciphers, and has been one of the most di?cult andactive research areas in cryptology. This dissertation focuses on the theory and applica-tions of stream cipher cryptanalytic technology. The contributions of the dissertationare listed as follows:(1) Algebraic attacks are proposed on two kinds of nonlinear filter generators withsymmetric Boolean functions as the filter functions. Di?erent from the classicalalgebraic attacks, the proposed attacks utilize a combinatorial property of thelinear feedback shift register (LFSR) and the symmetric Boolean function to de-rive a low–degree algebraic relation, and hence the complexities of the proposedattacks are independent of the algebraic immunity (AI) of the filter functions.It is shown that the improper combining the LFSR with the filter function canrender the filter generator vulnerable to algebraic attacks. As a result, the com-binatorial way of the LFSR and the filter function with large AI must be properlydeployed in order to withstand the proposed algebraic attacks.(2) A resynchronization attack is proposed on stream ciphers filtered by Maiorana–McFarland (M–M) functions and equipped with a linear resynchronization mech-anism. The proposed attack utilizes the linearity weakness of the resynchroniza-tion mechanism and the partial linearity of M–M functions, and then applies thelinear consistency test method to recover the secret key. It is shown that an M–M function should not be implemented by itself but rather in combination withother nonlinear components in stream ciphers. It is also shown that linear resyn-chronization mechanisms should be designed elaborately in synchronous streamciphers to withstand the proposed attack despite their simple implementationand high e?ciency.(3) Based on the analysis of the algebraic structure of the stream cipher Grain,three design weaknesses of the keystream generator are pointed out. Althoughwe fail to provide a general key–recovery attack on the generator, knowing anintermediate state of the keystream generator does help us successfully launch akey–recovery attack on Grain. The Grain keystream generator turns out to havedesign weaknesses. Furthermore, an improvement on the generator is presentedto withstand the proposed key–recovery attack. (4) The security of the multiplexer generator is investigated with respect to algebraicattacks. All the linearly independent lowest degree annihilators of the multiplexfunction are determined and accordingly an algebraic attack on the multiplexergenerator is presented. Comparisons show that the proposed attack gains someadvantages over the existing attacks in some situations.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络