错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cube Attacks on Round-Reduced Grain-128AEAD

  • Wil Liam Teng,
  • Iftekhar Salam,
  • Wei-Chuen Yau,
  • Jia Yew Teh

摘要

Lightweight cryptography aims to design secure and efficient cryptographic algorithms for resource-constrained devices. Traditional cryptographic algorithms may not be readily usable in resource-constrained environments. To standardise cryptographic solutions tailored for such resource-constraint environments, the National Institute of Standards and Technology (NIST) launched the Lightweight Cryptography (LWC) project. Grain-128AEAD is a stream cipher-based finalist in the NIST LWC project. In this work, we examine the security of the initial version of Grain-128AEAD against cube attacks. We present distinguishing attacks on a reduced-round version of the cipher, assuming that the keystream can be observed immediately after the reduced-round initialisation of the pre-output generator. We obtained various cubes of sizes 25 to 45 for reduced-round Grain-128AEAD. The best cube reported in this work can distinguish the output of a 165-round initialisation of Grain-128AEAD with a cube size of 35. The complexity of the distinguishing attack is \(\mathcal {O}(2^{35})\) . The results are confirmed experimentally. We conclude that even with fewer rounds of initialisation for the first version of Grain-128AEAD, the cipher still has a good security margin against cube attacks.