<p>In SAC’14, Biham and Carmeli presented a novel attack on DES, involving a variation of Partitioning Cryptanalysis. This was further extended in ToSC’18 by Biham and Perle into the Conditional Linear Cryptanalysis in the context of Feistel ciphers. In this work, we formalize this cryptanalytic technique for Substitution-Permutation Networks and derive several properties. A conditional approximation is then used to approximate the <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9550_Article_IEq1.gif" Format="GIF" Height="20" Rendition="HTML" Resolution="72" Type="Linedraw" Width="252" /> </InlineMediaObject> <EquationSource Format="TEX">\({ \texttt {inv}}:GF(2^8)\rightarrow GF(2^8):x\mapsto x^{254}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="monospace">inv</mi> <mo>:</mo> <mi>G</mi> <mi>F</mi> <mrow> <mo stretchy="false">(</mo> <msup> <mn>2</mn> <mn>8</mn> </msup> <mo stretchy="false">)</mo> </mrow> <mo stretchy="false">→</mo> <mi>G</mi> <mi>F</mi> <mrow> <mo stretchy="false">(</mo> <msup> <mn>2</mn> <mn>8</mn> </msup> <mo stretchy="false">)</mo> </mrow> <mo>:</mo> <mi>x</mi> <mo>↦</mo> <msup> <mi>x</mi> <mn>254</mn> </msup> </mrow> </math></EquationSource> </InlineEquation> function which forms the only source of nonlinearity in the AES. By extending the approximation to encompass the full AES round function, a linear distinguisher for 4-round AES using <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="145_2025_9550_Article_IEq2.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="42" /> </InlineMediaObject> <EquationSource Format="TEX">\(2^{125.72}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mn>2</mn> <mrow> <mn>125.72</mn> </mrow> </msup> </math></EquationSource> </InlineEquation> known-plaintexts is constructed; the existence of which is often understood to be impossible. We furthermore demonstrate how to recover 32 key bits directly from this distinguisher with no data or time overhead. In addition to suggesting a new approach to advancing the cryptanalysis of the AES, this result moreover demonstrates a caveat in the standard interpretation of the Wide Trail Strategy—the design framework underlying many SPN-based ciphers published in recent years.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A New Linear Distinguisher for Four-Round AES

  • Tomer Ashur,
  • Erik Takke

摘要

In SAC’14, Biham and Carmeli presented a novel attack on DES, involving a variation of Partitioning Cryptanalysis. This was further extended in ToSC’18 by Biham and Perle into the Conditional Linear Cryptanalysis in the context of Feistel ciphers. In this work, we formalize this cryptanalytic technique for Substitution-Permutation Networks and derive several properties. A conditional approximation is then used to approximate the \({ \texttt {inv}}:GF(2^8)\rightarrow GF(2^8):x\mapsto x^{254}\) inv : G F ( 2 8 ) G F ( 2 8 ) : x x 254 function which forms the only source of nonlinearity in the AES. By extending the approximation to encompass the full AES round function, a linear distinguisher for 4-round AES using \(2^{125.72}\) 2 125.72 known-plaintexts is constructed; the existence of which is often understood to be impossible. We furthermore demonstrate how to recover 32 key bits directly from this distinguisher with no data or time overhead. In addition to suggesting a new approach to advancing the cryptanalysis of the AES, this result moreover demonstrates a caveat in the standard interpretation of the Wide Trail Strategy—the design framework underlying many SPN-based ciphers published in recent years.