In this paper, we describe new quantum generic attacks on 6 rounds balanced Feistel networks on 2n bits with internal functions or internal permutations on n bits. In order to obtain our new quantum attacks, we revisit a result of Childs and Eisenberg that extends Ambainis’ collision finding algorithm to the subset finding problem. In more detail, we continue their work by carefully analyzing the time complexity of their algorithm. We also use four points structures attacks instead of two points structures attacks that lead to a complexity of \(\mathcal {O}(2^{8n/5})\) instead of \(\mathcal {O}(2^{2n})\) . Therefore, this paper illustrates that it’s possible to attack 6 rounds in strictly less than \(2^{2n}\) quantum computations, whereas previously only quantum attacks on five rounds were known. Moreover, we consider a classical attack on 6 rounds with internal functions proposed by Patarin (from ASIACRYPT 2001) and provide a new, improved analysis in the case where it is applied with internal permutations. The complexity here will be in \(\mathcal {O}(2^{2n})\) instead of \(\mathcal {O}(2^{3n})\) previously known.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Classical and Quantum Generic Attacks on 6-Round Feistel Schemes

  • Maya Chartouny,
  • Benoît Cogliati,
  • Jacques Patarin

摘要

In this paper, we describe new quantum generic attacks on 6 rounds balanced Feistel networks on 2n bits with internal functions or internal permutations on n bits. In order to obtain our new quantum attacks, we revisit a result of Childs and Eisenberg that extends Ambainis’ collision finding algorithm to the subset finding problem. In more detail, we continue their work by carefully analyzing the time complexity of their algorithm. We also use four points structures attacks instead of two points structures attacks that lead to a complexity of \(\mathcal {O}(2^{8n/5})\) instead of \(\mathcal {O}(2^{2n})\) . Therefore, this paper illustrates that it’s possible to attack 6 rounds in strictly less than \(2^{2n}\) quantum computations, whereas previously only quantum attacks on five rounds were known. Moreover, we consider a classical attack on 6 rounds with internal functions proposed by Patarin (from ASIACRYPT 2001) and provide a new, improved analysis in the case where it is applied with internal permutations. The complexity here will be in \(\mathcal {O}(2^{2n})\) instead of \(\mathcal {O}(2^{3n})\) previously known.