Multiplicative Differentials

نویسندگان

  • Nikita Borisov
  • Monica Chew
  • Robert Johnson
  • David A. Wagner
چکیده

We present a new type of differential that is particularly suited to analyzing ciphers that use modular multiplication as a primitive operation. These differentials are partially inspired by the differential used to break Nimbus, and we generalize that result. We use these differentials to break the MultiSwap cipher that is part of the Microsoft Digital Rights Management subsystem, to derive a complementation property in the xmx cipher using the recommended modulus, and to mount a weak key attack on the xmx cipher for many other moduli. We also present weak key attacks on several variants of IDEA. We conclude that cipher designers may have placed too much faith in multiplication as a mixing operator, and that it should be combined with at least two other incompatible group operations.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Two-Round AES Differentials

In this paper we study the probability of differentials and characteristics over 2 rounds of the AES with the objective to understand how the components of the AES round transformation interact. We extend and correct the analysis of the differential properties of the multiplicative inverse in GF(2) given in [17]. We show that AES has characteristics with a fixed-key probability that is many tim...

متن کامل

WDVV Equations from Algebra of Forms

A class of solutions to the WDVV equations is provided by period matrices of hyperelliptic Riemann surfaces, with or without punctures. The equations themselves reflect associativity of explicitly described multiplicative algebra of (possibly meromorphic) 1-differentials, which holds at least in the hyperelliptic case. This construction is direct generalization of the old one, involving the rin...

متن کامل

Almost n-Multiplicative Maps‎ between‎ ‎Frechet Algebras

For the Fr'{e}chet algebras $(A, (p_k))$ and $(B, (q_k))$ and $n in mathbb{N}$, $ngeq 2$, a linear map $T:A rightarrow B$ is called textit{almost $n$-multiplicative}, with respect to $(p_k)$ and $(q_k)$, if there exists $varepsilongeq 0$ such that$$q_k(Ta_1a_2cdots a_n-Ta_1Ta_2cdots Ta_n)leq varepsilon p_k(a_1) p_k(a_2)cdots p_k(a_n),$$for each $kin mathbb{N}$ and $a_1, a_2, ldots, a_nin A$. Th...

متن کامل

On multiplicative (strong) linear preservers of majorizations

‎In this paper, we study some kinds of majorizations on $textbf{M}_{n}$ and their linear or strong linear preservers. Also, we find the structure of linear or strong linear preservers which are multiplicative, i.e.  linear or strong linear preservers like $Phi $ with the property $Phi (AB)=Phi (A)Phi (B)$ for every $A,Bin textbf{M}_{n}$.

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2002