As one of the candidates for authenticated encryption in the second round of the CAESAR competition, Joltik has an internal lightweight tweakable block cipher Joltik-BC. In ASIACRYPT 2014, designers stated that the real threat to Joltik-BC comes from attacks that exploit the tweakey schedule, i.e. related-tweakey differential attacks. However, there has been no such attack against Joltik-BC currently. In the paper, we evaluate the resistance to Joltik-BC against boomerang attacks. Considering that not all distinguishers with high probability have a significant effect in key recovery attacks, we incorporate the complexity of key recovery into the search for distinguishers and turn to search for the entire truncated attack paths. Specifically, by considering truncated differential propagation, we control the number of active nibbles on the sides of plaintext and ciphertext to reduce key guessing. Then we apply it to search for appropriate distinguishers of Joltik-BC. Finally, we propose a 10-round related-tweakey boomerang attack for Joltik-BC-128 and a 14-round related-tweakey rectangle attack for Joltik-BC-192. To reduce the time complexity, we also utilize the property of components to guess partial key bits and deduce other key bits. This is the first work to evaluate the resistance of related-tweakey boomerang attack for Joltik-BC and both of them increase the round number of key recovery attacks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Related-Tweakey Boomerang and Rectangle Attacks on Reduced-Round Joltik-BC

  • Kangkang Shi,
  • Jiongjiong Ren,
  • Shaozhen Chen

摘要

As one of the candidates for authenticated encryption in the second round of the CAESAR competition, Joltik has an internal lightweight tweakable block cipher Joltik-BC. In ASIACRYPT 2014, designers stated that the real threat to Joltik-BC comes from attacks that exploit the tweakey schedule, i.e. related-tweakey differential attacks. However, there has been no such attack against Joltik-BC currently. In the paper, we evaluate the resistance to Joltik-BC against boomerang attacks. Considering that not all distinguishers with high probability have a significant effect in key recovery attacks, we incorporate the complexity of key recovery into the search for distinguishers and turn to search for the entire truncated attack paths. Specifically, by considering truncated differential propagation, we control the number of active nibbles on the sides of plaintext and ciphertext to reduce key guessing. Then we apply it to search for appropriate distinguishers of Joltik-BC. Finally, we propose a 10-round related-tweakey boomerang attack for Joltik-BC-128 and a 14-round related-tweakey rectangle attack for Joltik-BC-192. To reduce the time complexity, we also utilize the property of components to guess partial key bits and deduce other key bits. This is the first work to evaluate the resistance of related-tweakey boomerang attack for Joltik-BC and both of them increase the round number of key recovery attacks.