Full-round impossible diferential attack on shadow block cipher  

作  者:Yuting Liu Yongqiang Li Huiqin Chen Mingsheng Wang 

机构地区:[1]State Key Laboratory of Information Security,Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China [2]School of Cyber Security,University of Chinese Academy of Sciences,Beijing,China

出  处:《Cybersecurity》2025年第1期247-261,共15页网络空间安全科学与技术(英文)

基  金:supported by the National Natural Science Foundation of China(No.12371525).

摘  要:Lightweight block ciphers are the essential encryption algorithm for devices with limited resources.Its goal is to ensure the security of data transmission through resource-constrained devices.Impossible diferential cryptanalysis is one of the most efective cryptanalysis on block ciphers,and assessing the ability of resisting this attack is a basic design criterion.Shadow is a lightweight block cipher proposed by Guo et al.(IEEE Internet Things J 8(16):13014-13023,2021).It utilizes a combination of ARX operations and generalized Feistel structure to overcome the weakness of the traditional Feistel structure that only difuses half in one round.In this paper,we focus on the differential property of Shadow and its security against impossible diferential cryptanalysis.First,we use the SAT method to automatically search for a full-round impossible diferential distinguisher of Shadow-32.Then,based on the experimental results,we prove that Shadow has a diferential property with probability 1 based on the propagation of the state.Further,we can obtain an impossible diferential distinguisher for an arbitrary number of rounds of Shadow.Finally,we perform a full key recovery attack on the full-round Shadow-32 and Shadow-64.Both experimentally and theoretically,our results indicate that Shadow is critically fawed,and regardless of the security strength of the internal components and the number of rounds applied,the overall cipher remains vulnerable to impossible diferential cryptanalysis.

关 键 词:Lightweight block cipher SHADOW Impossible diferential cryptanalysis SAT 

分 类 号:TP3[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象