CORC  > 软件研究所  > 软件所图书馆  > 会议论文
weak keys of the full misty1 block cipher for related-key differential cryptanalysis
Lu Jiqiang ; Yap Wun-She ; Wei Yongzhuang
2013
会议名称Cryptographers' Track at the RSA Conference 2013, CT-RSA 2013
会议日期February 25, 2013 - March 1, 2013
会议地点San Francisco, CA, United states
关键词Lyapunov methods Security of data
页码389-404
中文摘要The MISTY1 block cipher has a 64-bit block length, a 128-bit user key and a recommended number of 8 rounds. It is a Japanese CRYPTREC-recommended e-government cipher, a European NESSIE selected cipher, and an ISO international standard. Despite of considerable cryptanalytic efforts during the past fifteen years, there has been no published cryptanalytic attack on the full MISTY1 cipher algorithm. In this paper, we present a related-key differential attack on the full MISTY1 under certain weak key assumptions: We describe 2 103.57 weak keys and a related-key differential attack on the full MISTY1 with a data complexity of 261 chosen ciphertexts and a time complexity of 290.93 encryptions. For the first time, our result exhibits a cryptographic weakness in the full MISTY1 cipher (when used with the recommended 8 rounds), and shows that the MISTY1 cipher is distinguishable from an ideal cipher and thus cannot be regarded to be an ideal cipher. © 2013 Springer-Verlag.
英文摘要The MISTY1 block cipher has a 64-bit block length, a 128-bit user key and a recommended number of 8 rounds. It is a Japanese CRYPTREC-recommended e-government cipher, a European NESSIE selected cipher, and an ISO international standard. Despite of considerable cryptanalytic efforts during the past fifteen years, there has been no published cryptanalytic attack on the full MISTY1 cipher algorithm. In this paper, we present a related-key differential attack on the full MISTY1 under certain weak key assumptions: We describe 2 103.57 weak keys and a related-key differential attack on the full MISTY1 with a data complexity of 261 chosen ciphertexts and a time complexity of 290.93 encryptions. For the first time, our result exhibits a cryptographic weakness in the full MISTY1 cipher (when used with the recommended 8 rounds), and shows that the MISTY1 cipher is distinguishable from an ideal cipher and thus cannot be regarded to be an ideal cipher. © 2013 Springer-Verlag.
收录类别EI
会议录Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
语种英语
ISSN号0302-9743
ISBN号9783642360947
内容类型会议论文
源URL[http://ir.iscas.ac.cn/handle/311060/15898]  
专题软件研究所_软件所图书馆_会议论文
推荐引用方式
GB/T 7714
Lu Jiqiang,Yap Wun-She,Wei Yongzhuang. weak keys of the full misty1 block cipher for related-key differential cryptanalysis[C]. 见:Cryptographers' Track at the RSA Conference 2013, CT-RSA 2013. San Francisco, CA, United states. February 25, 2013 - March 1, 2013.
个性服务
查看访问统计
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。


©版权所有 ©2017 CSpace - Powered by CSpace