<p>Differential-linear cryptanalysis is an important cryptanalytic tool in cryptography, and has been extensively researched since its introduction by Langford and Hellman in 1994. There are nevertheless very few methods to study the middle part where the differential characteristics and linear approximations connect. In this paper, we study differential-linear cryptanalysis from an algebraic perspective. We first introduce a technique called Differential Algebraic Transitional Form (DATF), then develop a new theory for estimating the differential-linear bias and techniques for key recovery in differential-linear cryptanalysis. The techniques are applied to the LWC standard <Emphasis FontCategory="NonProportional">Ascon</Emphasis>, the AES finalist <Emphasis FontCategory="NonProportional">Serpent</Emphasis>, the eSTERAM finalist <Emphasis FontCategory="NonProportional">Grain</Emphasis>&#xa0;<Emphasis FontCategory="NonProportional">v1</Emphasis>, and the LWC finalist <Emphasis FontCategory="NonProportional">Grain-128AEADv2</Emphasis>. The biases of the differential-linear approximations are estimated for <Emphasis FontCategory="NonProportional">Ascon</Emphasis> and <Emphasis FontCategory="NonProportional">Serpent</Emphasis>. The theoretical estimates of the bias are equal to or extremely close to their experimental results, two of which are proved to be the exact values of the bias. Our general techniques can also be used to estimate the biases of <Emphasis FontCategory="NonProportional">Grain</Emphasis>&#xa0;<Emphasis FontCategory="NonProportional">v1</Emphasis> and <Emphasis FontCategory="NonProportional">Grain-128AEADv2</Emphasis> in differential cryptanalysis. The improved key recovery attacks on round-reduced variants of these ciphers are then proposed. To the best of our knowledge, they are thus far the best known differential-linear cryptanalysis of <Emphasis FontCategory="NonProportional">Serpent</Emphasis>, as well as the best initialization analysis of <Emphasis FontCategory="NonProportional">Grain</Emphasis>&#xa0;<Emphasis FontCategory="NonProportional">v1</Emphasis> and <Emphasis FontCategory="NonProportional">Grain-128AEADv2</Emphasis>.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Differential-Linear Cryptanalysis from an Algebraic Perspective

  • Meicheng Liu,
  • Chengan Hou,
  • Xiaojuan Lu,
  • Shichang Wang,
  • Dongdai Lin

摘要

Differential-linear cryptanalysis is an important cryptanalytic tool in cryptography, and has been extensively researched since its introduction by Langford and Hellman in 1994. There are nevertheless very few methods to study the middle part where the differential characteristics and linear approximations connect. In this paper, we study differential-linear cryptanalysis from an algebraic perspective. We first introduce a technique called Differential Algebraic Transitional Form (DATF), then develop a new theory for estimating the differential-linear bias and techniques for key recovery in differential-linear cryptanalysis. The techniques are applied to the LWC standard Ascon, the AES finalist Serpent, the eSTERAM finalist Grain v1, and the LWC finalist Grain-128AEADv2. The biases of the differential-linear approximations are estimated for Ascon and Serpent. The theoretical estimates of the bias are equal to or extremely close to their experimental results, two of which are proved to be the exact values of the bias. Our general techniques can also be used to estimate the biases of Grain v1 and Grain-128AEADv2 in differential cryptanalysis. The improved key recovery attacks on round-reduced variants of these ciphers are then proposed. To the best of our knowledge, they are thus far the best known differential-linear cryptanalysis of Serpent, as well as the best initialization analysis of Grain v1 and Grain-128AEADv2.