节点文献

用不可能差分法分析17轮SMS4算法

Impossible differential attack on the 17-round block cipher SMS4

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 陈杰胡予濮张跃宇

【Author】 CHEN Jie,HU Yu-pu,ZHANG Yue-yu(Ministry of Education Key Lab.of Computer Network and Information Security,Xidian Univ.,Xi′an 710071,China)

【机构】 西安电子科技大学计算机网络与信息安全教育部重点实验室西安电子科技大学计算机网络与信息安全教育部重点实验室 陕西西安710071陕西西安710071

【摘要】 SMS4是我国在2006年公布的第一个商用分组密码算法.通过分析SMS4每一轮输入输出对的差分的变化,首次给出一个14轮SMS4的不可能差分特性:如果输入的明文对的差分为(a,a,a,0),那么14轮之后的输出差分不可能为(a,a,a,0).利用该性质,在14轮不可能差分密码分析的基础上,前面加了两轮,后面加了一轮,提出了一种不可能差分密码分析17轮SMS4的方法.该方法分析17轮SMS4需要2103的选择明文,2124的17轮SMS4加密以及289分组的记忆存储空间,猜测密钥的错误概率仅为2-88.7.

【Abstract】 The SMS4 is the first commercial block cipher published by our government in 2006.By analyzing the changes of the difference between input and output pairs in each round,this paper first presents an impossible differential property for the 14-round SMS4 if the difference of the input plaintext pair is(a,a,a,0),it is impossible that the difference of 14-round output pair is(a,a,a,0).Based on this property,a new method is proposed for cryptanalyzing the 17-round SMS4,which is to add two rounds and one round to each end of the impossible differential cryptanalysis for the 14-round SMS4.This attack on the reduced 17-round SMS4 requires about 2103 chosen plaintexts,performs 2124 17-round SMS4 encryptions,and demands 289 words of memory.Furthermore,the probability of its failure to recover the secret key is only 2-88.7.

【基金】 国家自然科学基金资助(60673072);国家密码发展基金资助;国家“973”重点基础研究发展规划项目基金资助(2007CB311201)
  • 【文献出处】 西安电子科技大学学报 ,Journal of Xidian University , 编辑部邮箱 ,2008年03期
  • 【分类号】TN918
  • 【被引频次】22
  • 【下载频次】236
节点文献中: 

本文链接的文献网络图示:

本文的引文网络