节点文献

新区分器的构造及其在分组密码分析中的应用

New Construction of Distinguishers and Its Application in Analysis of Block Ciphers

【作者】 韦永壮

【导师】 胡予濮;

【作者基本信息】 西安电子科技大学 , 密码学, 2009, 博士

【摘要】 分组密码属对称密码体制,是现代密码学的一个重要组成部分。由于分组密码具有加解密速度快、容易标准化、便于实现、主要安全指标容易评估等优点,目前已经成为通信与信息系统主流的信息加密体制之一。分组密码的研究一般包含两个方面:编码技术和分析技术。分组密码的分析技术(又称为攻击技术)一直是分组密码研究的热点。分组密码分析的一般策略包括两步:第1步寻找密码算法的区分器,即设法发现密码算法的某种非随机性;第2步利用该区分器完全或部分地恢复密码算法的秘密信息。如何构造新型有效的区分器往往是分组密码分析的关键所在。本文针对FOX系列算法、AES算法、SHACAL-2算法开展研究,根据这些算法的不同特点构造了多个新区分器,并据此给出新的攻击方法。主要研究结果如下:1.FOX系列算法的不可能差分分析:(1)利用FOX128的算法结构和轮函数特点,构造了一个新的4轮不可能差分区分器。基于该区分器,给出一种攻击5轮FOX128的新方法。(2)利用FOX64的算法结构和轮函数特点,构造了一个新的4轮不可能差分区分器。在此基础上,针对5轮、6轮、7轮FOX64分别给出新的攻击。2.AES的相关密钥矩形新攻击:(1)利用AES-192密钥编排的弱点,构造了一个新的7轮相关密钥矩形区分器;基于该区分器和单字节密钥猜测技术,针对9轮AES-192给出了一种新的攻击方法。(2)利用AES-256密钥编排的弱点,构造了一个新的8轮相关密钥矩形区分器;由此针对10轮AES-256给出了一种新的攻击方法。(3)改进了FSE2007论文中针对10轮AES-192的相关密钥矩形攻击,使其所需的数据量和时间复杂度均有所降低。3.SHACAL-2的相关密钥矩形新攻击:(1)利用SHACAL-2密码算法轮变换的特点,构造了一个新的34轮区分器。基于该区分器和部分密钥分别猜测的技术,针对40轮、42轮SHACAL-2分别给出了新的攻击方法。(2)基于SHACAL-2密码算法轮变换和密钥编排的特点,构造了一个新的35轮区分器。由此针对44轮SHACAL-2给出了一种新的攻击方法。4.AES的差分-线性攻击:利用AES S盒的密码学特性和列混淆(MC)部件的特点,构造了一个新的4轮差分-线性区分器;基于该区分器,首次刻画了单密钥下7轮AES-192与7轮AES-256抵抗差分-线性攻击的能力。5.8轮AES的差分碰撞攻击:利用AES算法轮变换的特点,构造了一个新型的5轮区分器;结合AES的密钥编排特点和时空折中技术,分别针对单密钥下7轮AES-192,8轮AES-192,8轮AES-256给出了新的差分碰撞攻击。

【Abstract】 Block cipher which belongs to symmetric ciphers is an important branch of modern cryptology. Since its many attractive features such as high rates for encryption and decryption, easiness for standardization, and efficiency for implementation, easy evaluation for main security parameters and so on, block cipher has become one of the most widely used encryption algorithms in modern communication and information system.The research of block ciphers generally includes two parts: the design techniques of block ciphers and the security analysis of block ciphers. The techniques for cryptanalysising block ciphers (or the attacking techniques on block ciphers) are always an active research subject. General attack strategy for block ciphers has two steps. Step1: build a distinguisher, i.e., try to find out a non-random property of the block ciphers. Step2: recover round keys, i.e., use the distinguishers to recover full or partial round secret keys. How to obtain some effective distinguishers is very important to the cryptanalysis of block ciphers. The dissertation investigates some new attacks on the family of FOX block ciphers, Advanced Encryption Standard (AES), and SHACAL-2 algorithm by constructing some new distinguishers. The contributions of the dissertation are outlined as follows:1. Impossible differential cryptanalysis of the family of FOX encryption algorithm.(1) A new 4-round impossible differential distinguisher is constructed by using the properties of round function of FOX128. From this distinguisher, an attack on the 5-round FOX128 is presented.(2) Similarly, a new 4-round distinguisher is constructed by using the properties of round transformation of FOX64. From this distinguisher, some new attacks on the 5, 6, 7-round FOX64 are presented, respectively.2. New related-key rectangle attacks on AES.(1) A new 7-round related-key rectangle distinguisher is constructed by exploiting the weakness in the key schedule of AES-192. Based on this distinguisher and a technique of guessing a single byte, we propose a new attack on the 9-round AES-192.(2) Similarly, a new 8-round related-key rectangle distinguisher is constructed by exploiting the weakness in the key schedule of AES-256. Based on this distinguisher, we also propose a new attack on the 10-round AES-256.(3) An improvement on the 10-round reduced AES-192 attack from FSE2007 is made to reduce both the data complexity and the time complexity. 3. New related-key rectangle attacks on SHACAL-2.(1) A new 34-round related-key rectangle distinguisher is constructed by exploiting the properties of the round transformation of SHACAL-2. Moreover, two new relate-key rectangle attacks on the 40-round and 42-round SHACAL-2 are respectively presented by using the distinguisher and a technique of key-byte guessing.(2) Similarly, a new 35-round related-key rectangle distinguisher is constructed by exploiting the properties of the round transformation of SHACAL-2. Finally, a new relate-key rectangle attack on the 44-round reduced SHACAL-2 is presented by using the distinguisher.4. Differential-linear attack on AES.A 4-round differential-linear distinguisher is proposed by using the special properties of the S-box and MC operations of AES. This distinguisher is then used to attack on the 7-round AES-192 and 7-round AES-256, which, as far as the author knows, is the the first known differential-linear attacks on the 7-round AES-192 and 7-round AES-256 in a single key attack scenario.5. Differential collision attack on 8-round AES.A new 5-round distinguisher for AES is presented by using the properties of its round transformation. Some new differential collision attacks on the 7-round AES-192, 8-round AES-192, and 8-round AES-256 in a single key attack scenario are respectively presented by exploiting the distinguisher and a time-memory tradeoff.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络