检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]信息工程大学,郑州450001
出 处:《密码学报》2015年第2期139-158,共20页Journal of Cryptologic Research
基 金:Lai-Massey分组密码模型的安全性研究(61272488);分组密码不可能差分分析技术研究(61402523)
摘 要:不可能差分分析和零相关线性分析是分析分组密码算法的重要工具,而对分组密码算法进行这两种攻击的关键则是该算法中不可能差分对应和零相关线性逼近的存在.EGFN模型是在2013年SAC会议上被Berger等人提出的,该模型的扩散速度比已有的Feistel模型快.Berger等人给出了输入分块个数为4、8和16的EGFN模型的具体结构,并分析了其针对各种攻击的安全性,但并没有给出EGFN模型中具体的不可能差分对应和零相关线性逼近.本文定义了4-EGFN/8-EGFN/16-EGFN模型中相容的差分对应/相容的线性逼近和强不可能差分对应/强零相关线性逼近,给出了4-EGFN/8-EGFN/16-EGFN模型中相容的差分传递链和相容的线性逼近传递链之间的对偶关系,并首次给出了嵌套SP网络的4-EGFN/8-EGFN/16-EGFN模型的9轮强不可能差分对应和9轮强零相关线性逼近,以及保证9轮强不可能差分对应和9轮强零相关线性逼近存在时扩散层需要满足的充分条件,并列举了满足该充分条件的扩散层矩阵.Impossible differential and zero correlation linear cryptanalyses are important tools to analyze the security of block ciphers,and the basis of these two kinds of attacks is the existence of the impossibledifferentials and zero correlation linear approximations of the block cipher. EGFN structure is proposed at SAC 2013 by Berger et al., the diffusion speed of EGFN structure is faster than that of other Feistel structure. Berger et al. presented the specific structure of EGFN with 4/8/16 input blocks, and analysis their security against various attack methods. However, they did not give the specific impossible differential and zero correlation linear approximation of 4-EGFN/8-EGFN/16-EGFN. This paper defines compatible differential and compatible linear approximation of 4-EGFN/8-EGFN/16-EGFN, presents the dual relationship between the compatible differential characteristic and the compatible linear trail of 4-EGFN/8-EGFN/16-EGFN, and gives the 9-round strong impossible differentials and strong zero correlation linear approximations for EGFN structure. Moreover, this paper gives the sufficient conditions which the diffusion layer should satisfy to ensure the existence of the 9-round strong impossible differentials and strong zero correlation linear approximations, and lists some matrix that satisfy those sufficient conditions.
关 键 词:分组密码 EGFN结构 代替-置换网络 强不可能差分对应 强零相关线性逼近
分 类 号:TN918.1[电子电信—通信与信息系统]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.148.241.79