Zero Correlation Linear Cryptanalysis on LEA Family Ciphers
نویسندگان
چکیده
—In recent two years, zero correlation linear cryptanalysis has shown its great potential in cryptanalysis and it has proven to be effective against massive ciphers. LEA is a block cipher proposed by Deukjo Hong, who is the designer of an ISO standard block cipher HIGHT. This paper evaluates the security level on LEA family ciphers against zero correlation linear cryptanalysis. Firstly, we identify some 9-round zero correlation linear hulls for LEA. Accordingly, we propose a distinguishing attack on all variants of 9-round LEA family ciphers. Then we propose the first zero correlation linear cryptanalysis on 13-round LEA-192 and 14-round LEA-256. For 13-round LEA-192, we propose a key recovery attack with time complexity of 131.30 2 13-round LEA encryptions, data complexity of 128 2 plaintext-ciphertext pairs and memory complexity of 60.58 2 bytes. For 14-round LEA-256, we propose a key recovery attack with time complexity of 250.19 2 14-round LEA encryptions, data complexity of 128 2 plaintext-ciphertext pairs and memory complexity of 142.35 2 bytes. As far as we know, these are the best results on LEA using zero correlation linear cryptanalysis so far.
منابع مشابه
Zero Correlation Linear Cryptanalysis with Reduced Data Complexity
Zero correlation linear cryptanalysis is a novel key recovery technique for block ciphers proposed in [5]. It is based on linear approximations with probability of exactly 1/2 (which corresponds to the zero correlation). Some block ciphers turn out to have multiple linear approximations with correlation zero for each key over a considerable number of rounds. Zero correlation linear cryptanalysi...
متن کاملNew Automatic Search Tool for Impossible Differentials and Zero-Correlation Linear Approximations
Impossible differential cryptanalysis and zero-correlation linear cryptanalysis are two of the most useful cryptanalysis methods in the field of symmetric ciphers. Until now, there are several automatic search tools for impossible differentials such as U-method and UID-method, which are all independent of the non-linear S-boxes. Since the differential and linear properties can also contribute t...
متن کاملZero-Correlation Linear Cryptanalysis of Block Ciphers
Linear cryptanalysis, along with differential cryptanalysis, is an important tool to evaluate the security of block ciphers. This work introduces a novel extension of linear cryptanalysis – zero-correlation linear cryptanalysis – a technique applicable to many block cipher constructions. It is based on linear approximations with a correlation value of exactly zero. For a permutation on n bits, ...
متن کاملCharacterizations of the Degraded Boolean Function and Cryptanalysis of the SAFER Family
This paper investigates the degradation properties of Boolean functions from the aspects of the distributions of differences and linear masks, and shows two characterizations of the degraded Boolean function. One is that there exists a linear space of the input differences, where the differentials with the zero output difference have probability 1; Another one is that the input linear masks of ...
متن کاملLinear hulls with correlation zero and linear cryptanalysis of block ciphers
Linear cryptanalysis, along with differential cryptanalysis, is an important tool to evaluate the security of block ciphers. This work introduces a novel extension of linear cryptanalysis: zero-correlation linear cryptanalysis, a technique applicable to many block cipher constructions. It is based on linear approximations with a correlation value of exactly zero. For a permutation on n bits, an...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- JCM
دوره 11 شماره
صفحات -
تاریخ انتشار 2016