通信学报 ›› 2022, Vol. 43 ›› Issue (7): 41-48.doi: 10.11959/j.issn.1000-436x.2022112

• 学术论文 • 上一篇    下一篇

改进的减轮Kiasu-BC算法的中间相遇攻击

李曼曼1,2,3, 陈少真1,2,3   

  1. 1 信息工程大学网络空间安全学院,河南 郑州 450001
    2 密码科学技术国家重点实验室,北京 100878
    3 河南省网络密码技术重点实验室,河南 郑州 450001
  • 修回日期:2022-05-09 出版日期:2022-07-25 发布日期:2022-06-01
  • 作者简介:李曼曼(1986- ),女,河南开封人,博士,信息工程大学讲师,主要研究方向为网络空间安全、信息安全、对称密码的设计与分析等
    陈少真(1967- ),女,江苏无锡人,博士,信息工程大学教授,主要研究方向为密码学与信息安全
  • 基金资助:
    河南省网络密码技术重点实验室开放课题基金资助项目(LNCT2019-S03)

Improved meet-in-the-middle attack on reduced-round Kiasu-BC algorithm

Manman LI1,2,3, Shaozhen CHEN1,2,3   

  1. 1 College of Cyberspace Security, Information Engineering University, Zhengzhou 450001, China
    2 State Key Laboratory of Cryptology, Beijing 100878, China
    3 Henan Key Laboratory of Network Cryptography Technology, Zhengzhou 450001, China
  • Revised:2022-05-09 Online:2022-07-25 Published:2022-06-01
  • Supported by:
    Henan Key Laboratory of Network Cryptography Technology Open Funds(LNCT2019-S03)

摘要:

Kiasu-BC算法是加密认证竞赛CAESAR第一轮入选方案Kiasu的内置可调分组密码。Kiasu-BC算法是基于AES-128轮函数构造的可调分组密码算法,通过对Kiasu-BC算法的结构特征进行研究,利用调柄自由度以及内部密钥间的制约关系,降低预计算的复杂度。结合差分枚举技术,构造新的5轮中间相遇区分器,改进Kiasu-BC算法的8轮中间相遇攻击。改进后攻击的时间复杂度为2114,存储复杂度为263,数据复杂度为2108

关键词: 可调分组密码, Kiasu-BC算法, 中间相遇攻击, 差分枚举

Abstract:

Kiasu-BC algorithm is an internal tweakable block cipher of authenticated encryption algorithm Kiasu as one of first-round candidates in the CAESAR competition.The precomputation complexity is reduced by utilizing the freedom of the tweak and the internal key restriction through the research on structural characteristics of Kiasu-BC algorithm based on AES-128 round function.Combined with the differential enumeration technique, a new 5-round meet-in-the-middle distinguisher was constructed to improve the meet-in-the-middle attack on 8-round Kiasu-BC algorithm.The improved attack requires the time complexity of 2114, the memory complexity of 263 and the data complexity of 2108.

Key words: tweakable block cipher, Kiasu-BC algorithm, meet-in-the-middle attack, differential enumeration

中图分类号: 

No Suggested Reading articles found!