<p>In most linear key recovery attacks on block ciphers, the value of the target linear approximation is determined from the plaintext, ciphertext and key by a function. In some existing attacks, this map is replaced by a similar one in order to improve the time or memory complexity at the cost of a data complexity penalty. This paper proposes a general framework for key recovery map substitution, and introduces <i>Walsh spectrum</i>, which removes carefully-chosen coefficients from the Fourier transform of the <i>key recovery map</i>. The capabilities of this technique are illustrated by describing improved attacks on reduced-round Serpent (including the first 12-round attack on the 192-bit key variant), GIFT-128 and <span>Noekeon</span>, as well as the full DES.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Improving Linear Key Recovery Attacks using Walsh Spectrum Puncturing

  • Antonio Flórez-Gutiérrez,
  • Yosuke Todo

摘要

In most linear key recovery attacks on block ciphers, the value of the target linear approximation is determined from the plaintext, ciphertext and key by a function. In some existing attacks, this map is replaced by a similar one in order to improve the time or memory complexity at the cost of a data complexity penalty. This paper proposes a general framework for key recovery map substitution, and introduces Walsh spectrum, which removes carefully-chosen coefficients from the Fourier transform of the key recovery map. The capabilities of this technique are illustrated by describing improved attacks on reduced-round Serpent (including the first 12-round attack on the 192-bit key variant), GIFT-128 and Noekeon, as well as the full DES.