错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Impossible Differential Cryptanalysis of the Raindrop Block Cipher

  • Jiqiang Lu,
  • Xiao Zhang

摘要

The Raindrop block cipher is an award-winning algorithm of the recent Cryptographic Algorithm Design Competition in China. It employs a Feistel structure and has three versions Raindrop128-128, Raindrop128-256 and Raindrop256, which have a 128-bit block size with a 128- or 256-bit user key and a 256-bit block size with a 256-bit user key, respectively. In this paper, we observe that Raindrop can be transformed to an equivalent cipher with two rounds less than Raindrop (for each version), due to the position of the round key XOR operation. We also observe that when conducting impossible differential cryptanalysis of Raindrop, both inactive and active bit differences on plaintext and ciphertext as well as a few intermediate states may be exploited for some refined sorting conditions on plaintexts and ciphertexts to filter out preliminary satisfying plaintext/ciphertext pairs efficiently, and finally we exploit a few 12-round impossible differentials of Raindrop128 and Raindrop256 to make key-recovery attacks on 19-round Raindrop128-128, 21-round Raindrop128-256 and 20-round Raindrop256. Our attacks are better than any previously published cryptanalytic results on Raindrop in terms of the numbers of attacked rounds.