Higher-Order Mixture Differentials for AES-Based Block Ciphers and Applications to TweAES
摘要
In ToSC 2/2018, Grassi introduced mixture differentials for the AES. A mixture takes a pair of texts and derives a second pair from mixing parts of the first one. The conditional probability of the second pair to follow a certain (truncated) differential is then strongly influenced by that of the first pair. Mixtures found various follow-up applications for attacks, leading to Bar-On et al.’s fastest key-recovery attacks on 5-round AES, the fastest boomerangs on up to 6-round AES, or to Bardeh and Rønjom’s 6-round distinguisher. However, mixtures are not limited to the AES. Among the recent proposals of AES-based ciphers, TweAES augments the AES by a tiny tweak that is expanded with a simple code and added to the first two rows. Inspired by the observation that the tweak-expansion code of TweAES effectively thwarts tweak-induced mixtures, we propose higher-order mixtures as a generalization. To demonstrate their applicability, we describe a 6-round distinguisher and a 7-round key recovery attack on TweAES.