Differential-algebraic cryptanalysis of reduced-round of Serpent-256

来源 :Science China(Information Sciences) | 被引量 : 0次 | 上传用户:surfing203
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Differential cryptanalysis is a general cryptanalytic tool that makes use of diFFerentials over some rounds of a cipher, combined with some key bit guesses of one or two rounds. This paper introduces a new cryptanalysis strategy of block ciphers named differential-algebraic cryptanalysis. The idea of differential-algebraic cryptanalysis is to find a differential with high probability and build the multivariable system equations for the last few rounds. The subkey values of the last few rounds can be obtained by filtering the solutions of system equations instead of guessing all possible subkey values. We use the differential-algebraic cryptanalysis to break 8-round Serpent-256. Our attack can recover the 256-bit key with 283 chosen plaintexts, 2180.4 8-round Serpent- 256 encryptions and 2176.7 bytes memory. Compared with the previous differential cryptanalysis results, both the data complexity and the time complexity are reduced, but the memory requirements are increased. The time complexity and the memory requirements are very close, and a time-memory tradeoff is exploited. Differential cryptanalysis is a general cryptanalytic tool that makes use of diFFerentials over some rounds of a cipher, combined with some key bit guesses of one or two rounds. This paper introduces a new cryptanalysis strategy of block ciphers named differential-algebraic cryptanalysis. The idea of differential-algebraic cryptanalysis is to find a differential with high probability and build the multivariable system equations for the last few rounds. The subkey values ​​of the last few rounds can be obtained by filtering the solutions of system equations instead of guessing all possible subkey values. We use the differential-algebraic cryptanalysis to break 8-round Serpent-256. Our attack can recover the 256-bit key with 283 chosen plaintexts, 2180.4 8-round Serpent- 256 encryptions and 2176.7 bytes memory. Compared with the previous differential cryptanalysis results , both the data complexity and the time complexity are reduced, but the memory requirements are increased. The time comp lexity and the memory requirements are very close, and a time-memory tradeoff is exploited.
其他文献
劳动卫生与职业病学 (OccupationalHealthandOccupationalMedicine) ,是预防医学的一门重要分支学科 ;它雏形于远古时代 ,成形于十六世纪 ,但完整而严谨的“劳动卫生与职业病学”理论学术体系至今仍未确立 ,有待于丰富
鹤壁市位于河南省北部,是典型的因煤而立、依煤而兴的资源型城市,主要矿产资源有煤炭、石灰岩、白云岩。这些丰富的矿产资源曾经为我国社会主义建设做出了积极贡献,仅煤炭一
会议
循环经济是指能最有效利用资源和保护环境,以"减量化、再利用、资源化"为原则组织经济活动的经济发展模式。以磷化产业为主导的湖北宜昌经济开发区(以下简称宜昌开发区),发展
会议
以资源高效、循环利用为主要特征的循环经济已经成为21世纪的世界潮流和发展趋势。目前,我国正处于工业化和城市化快速发展阶段,重化工业加速发展是其主要特征,这也使我国面
发展循环经济,是坚持以人为本、执政为民宗旨的具体体现,是推进经济结构调整、转变增长方式的必由之路,是完成污染物减排任务、实现污染物源头控制的有效措施,是提高人民群众
会议
石嘴山市是国家"一五"时期布局的十大煤炭生产基地之一,1960年建市,是典型的先矿后市建制。40多年来,为国家和地方的经济建设输出了大量的原煤、电力和煤炭机械等工业产品。
会议
杭州钱江经济开发区隶属于杭州市人民政府,是经国家发改委批准的省级开发区。总规划面积23.8平方公里,首期启动5.91平方公里。钱江开发区坚持高起点规划、高强度投入、高标准
会议
循环经济在现实操作中遵循减量化、再利用、资源化的原则。减量化原则,要求在生产、流通和消费等过程中减少资源消耗和废物产生。在经济活动的源头就注意节约资源和减少污染
会议
目的 探讨脑卒中后抑郁应用乌灵胶囊联合黛力新治疗的临床疗效.方法 选取138例脑卒中后抑郁患者作为研究对象,随机分为对照组和观察组,均采取常规治疗;对照组应用乌灵胶囊,观
在自然生态系统中,磷是重要且不可短缺的元素,磷的再生循环过程是最慢的物质循环过程之一,在对人类有意义的时间范围内,磷是一种难以再生的稀缺资源。相对于水危机和石油危机
会议