The SPRING block cipher is an award-winning algorithm of the recent Cryptographic Algorithm Design Competition in China, and it has three versions: SPRING128-128 with a 128-bit block size and a 128-bit key size, SPRING128-256 with a 128-bit block size and a 256-bit key size, and SPRING256 with a 256-bit block size and a 256-bit key size. The best previously published cryptanalytic results on SPRING are (ordinary) differential attacks on 5-round SPRING128-128 and 10-round SPRING256 and differential and meet-in-the-middle attacks on 6-round SPRING128-256. In this paper, we observe that the two main elementary operations SubRow and Transpose of the SPRING round function enable some multiple-round one-byte truncated differential paths (i.e., input and output differences as well as any intermediate difference have only one active byte) with probability approximately \(2^{-24}\) for every round, then we construct a few 4-round truncated differentials with probability \(2^{-68}\) of SPRING128, 5-round truncated differentials with probability \(2^{-90}\) of SPRING128 and 11-round truncated differentials with probability \(2^{-223}\) of SPRING256, and finally we make truncated differential attacks on 6-round SPRING128-128/256, 7-round SPRING128-256 and 11/12/13-round SPRING256. Our attacks are better than any previously published cryptanalytic results on the corresponding versions of SPRING in terms of the numbers of attacked rounds.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Truncated Differential Cryptanalysis of the SPRING Block Cipher

  • Wenchang Zhou,
  • Jiqiang Lu

摘要

The SPRING block cipher is an award-winning algorithm of the recent Cryptographic Algorithm Design Competition in China, and it has three versions: SPRING128-128 with a 128-bit block size and a 128-bit key size, SPRING128-256 with a 128-bit block size and a 256-bit key size, and SPRING256 with a 256-bit block size and a 256-bit key size. The best previously published cryptanalytic results on SPRING are (ordinary) differential attacks on 5-round SPRING128-128 and 10-round SPRING256 and differential and meet-in-the-middle attacks on 6-round SPRING128-256. In this paper, we observe that the two main elementary operations SubRow and Transpose of the SPRING round function enable some multiple-round one-byte truncated differential paths (i.e., input and output differences as well as any intermediate difference have only one active byte) with probability approximately \(2^{-24}\) for every round, then we construct a few 4-round truncated differentials with probability \(2^{-68}\) of SPRING128, 5-round truncated differentials with probability \(2^{-90}\) of SPRING128 and 11-round truncated differentials with probability \(2^{-223}\) of SPRING256, and finally we make truncated differential attacks on 6-round SPRING128-128/256, 7-round SPRING128-256 and 11/12/13-round SPRING256. Our attacks are better than any previously published cryptanalytic results on the corresponding versions of SPRING in terms of the numbers of attacked rounds.