<p>Impossible differential cryptanalysis is a crucial cryptanalytical method for symmetric ciphers. Given an impossible differential, the key recovery attack typically proceeds in two steps: generating pairs of data and then identifying wrong keys using the guess-and-filtering method. At CRYPTO 2023, Boura <i>et al.</i> first proposed a new key recovery technique—the differential meet-in-the-middle attack, which recovers the key in a meet-in-the-middle manner. Inspired by this technique, we incorporate the meet-in-the-middle technique into impossible cryptanalysis and propose a generic impossible differential meet-in-the-middle attack (<Emphasis FontCategory="NonProportional">IDMA</Emphasis>) framework. We apply <Emphasis FontCategory="NonProportional">IDMA</Emphasis> to block ciphers <Emphasis FontCategory="NonProportional">SKINNY</Emphasis>, <Emphasis FontCategory="NonProportional">SKINNYe</Emphasis>-v2, and <Emphasis FontCategory="NonProportional">ForkSKINNY</Emphasis> and achieve remarkably efficient attacks. We improve the impossible differential attack on <Emphasis FontCategory="NonProportional">SKINNY</Emphasis>-<i>n</i>-3<i>n</i> by 2 rounds in the single-tweakey setting and 1 round in the related-tweakey setting. For <Emphasis FontCategory="NonProportional">SKINNYe</Emphasis>-v2, the impossible differential attacks now can cover 2 more rounds in the related-tweakey setting and the first 23/24/25-round attacks in the single-tweakey model are given. For <Emphasis FontCategory="NonProportional">ForkSKINNY</Emphasis>-<i>n</i>-3<i>n</i>, we improve the attacks by 2 rounds in the limited setting specified by the designers and 1 round in relaxed settings. These results confirm that the meet-in-the-middle technique can result in more efficient key recovery, reaching beyond what traditional methods can achieve on certain ciphers.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Generalized impossible differential attacks on block ciphers: application to SKINNY and ForkSKINNY

  • Ling Song,
  • Qinggan Fu,
  • Qianqian Yang,
  • Yin Lv,
  • Lei Hu

摘要

Impossible differential cryptanalysis is a crucial cryptanalytical method for symmetric ciphers. Given an impossible differential, the key recovery attack typically proceeds in two steps: generating pairs of data and then identifying wrong keys using the guess-and-filtering method. At CRYPTO 2023, Boura et al. first proposed a new key recovery technique—the differential meet-in-the-middle attack, which recovers the key in a meet-in-the-middle manner. Inspired by this technique, we incorporate the meet-in-the-middle technique into impossible cryptanalysis and propose a generic impossible differential meet-in-the-middle attack (IDMA) framework. We apply IDMA to block ciphers SKINNY, SKINNYe-v2, and ForkSKINNY and achieve remarkably efficient attacks. We improve the impossible differential attack on SKINNY-n-3n by 2 rounds in the single-tweakey setting and 1 round in the related-tweakey setting. For SKINNYe-v2, the impossible differential attacks now can cover 2 more rounds in the related-tweakey setting and the first 23/24/25-round attacks in the single-tweakey model are given. For ForkSKINNY-n-3n, we improve the attacks by 2 rounds in the limited setting specified by the designers and 1 round in relaxed settings. These results confirm that the meet-in-the-middle technique can result in more efficient key recovery, reaching beyond what traditional methods can achieve on certain ciphers.