Conditional Linear Cryptanalysis - Cryptanalysis Of Des With Less Than 2(42) Complexity

IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY(2018)

引用 14|浏览9
暂无评分
摘要
In this paper we introduce a new extension of linear cryptanalysis that may reduce the complexity of attacks by conditioning linear approximations on other linear approximations. We show that the bias of some linear approximations may increase under such conditions, so that after discarding the known plaintexts that do not satisfy the conditions, the bias of the remaining known plaintexts increases. We show that this extension can lead to improvements of attacks, which may require fewer known plaintexts and time of analysis. We present several types of such conditions, including one that is especially useful for the analysis of Feistel ciphers. We exemplify the usage of such conditions for attacks by a careful application of our extension to Matsui's attack on the full 16-round DES, which succeeds to reduce the complexity of the best attack on DES to less than 2(42). We programmed a test implementation of our attack and verified our claimed results with a large number of runs. We also introduce a new type of approximations, to which we call scattered approximations, and discuss its applications.
更多
查看译文
关键词
new cryptanalytic techniques, linear cryptanalysis, DES, conditional approximations, scattered approximations
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要