期刊文献+
共找到99篇文章
< 1 2 5 >
每页显示 20 50 100
Zero-Correlation Linear Cryptanalysis of Reduced-Round SIMON 认领 引用 被引量:5
1
作者 于晓丽 吴文玲 +3 位作者 石振青 张建 张蕾 汪艳凤 《Journal of Computer Science & Technology》 SCIE EI CSCD 2015年第6期1358-1369,共12页
In June 2013, the U.S. National Security Agency proposed two families of lightweight block ciphers, called SIMON and SPECK respectively. These ciphers are designed to perform excellently on both hardware and software ... In June 2013, the U.S. National Security Agency proposed two families of lightweight block ciphers, called SIMON and SPECK respectively. These ciphers are designed to perform excellently on both hardware and software platforms. In this paper, we mainly present zero-correlation linear cryptanalysis on various versions of SIMON. Firstly, by using miss- in-the-middle approach, we construct zero-correlation linear distinguishers of SIMON, and zero-correlation linear attacks are presented based oi1 careful analysis of key recovery phase. Secondly, multidimensional zero-correlation linear attacks are used to reduce the data complexity. Our zero-correlation linear attacks perform better than impossible differential attacks proposed by Abed et al. in ePrint Report 2013/568. Finally, we also use the divide-and-conquer technique to improve the results of linear cryptanalysis proposed by Javad et al. in ePrint Report 2013/663. 展开更多
关键词 lightweight block cipher SIMON linear cryptanalysis zero-correlation dual property
暂未订购 下载PDF
Cryptanalysis of Cryptosystems Based on General Linear Group 认领 引用 被引量:1
2
作者 Jianwei Jia Jinhui Liu Huanguo Zhang 《China Communications》 SCIE CSCD 2016年第6期217-224,共8页
Advances in quantum computers threaten to break public key cryptosystems such as RSA, ECC, and EIGamal on the hardness of factoring or taking a discrete logarithm, while no quantum algorithms are found to solve certai... Advances in quantum computers threaten to break public key cryptosystems such as RSA, ECC, and EIGamal on the hardness of factoring or taking a discrete logarithm, while no quantum algorithms are found to solve certain mathematical problems on non-commutative algebraic structures until now. In this background, Majid Khan et al.proposed two novel public-key encryption schemes based on large abelian subgroup of general linear group over a residue ring. In this paper we show that the two schemes are not secure. We present that they are vulnerable to a structural attack and that, it only requires polynomial time complexity to retrieve the message from associated public keys respectively. Then we conduct a detailed analysis on attack methods and show corresponding algorithmic description and efficiency analysis respectively. After that, we propose an improvement assisted to enhance Majid Khan's scheme. In addition, we discuss possible lines of future work. 展开更多
关键词 cryptography post quantum computational cryptography cryptanalysis non-abelian algebraic structures linear equations
暂未订购 下载PDF
Linear-Differential Cryptanalysis for SPN Cipher Structure and AES 认领 引用
3
作者 WEI Yongzhuang HU Yupu 《Wuhan University Journal of Natural Sciences》 CAS 2007年第1期37-40,共4页
A new attack on block ciphers is introduced, which is termed linear-differential cryptanalysis. It bases the combining of linear cryptanalysis and differential cryptanalysis, and works by using linear-differential pro... A new attack on block ciphers is introduced, which is termed linear-differential cryptanalysis. It bases the combining of linear cryptanalysis and differential cryptanalysis, and works by using linear-differential probability (LDP). Moreover, we present a new method for upper bounding the maximum linear-differential probability (MLDP) for 2 rounds of substitution permutation network (SPN) cipher structure. When our result applies to 2-round advanced encryption standard(AES), It is shown that the upper bound of MLDP is up to 1.68×2^-19, which extends the known results for the 2-round SPN. Furthermore, when using a recursive technique, we obtain that the MLDP for 4 rounds of AES is bounded by 2^-73. 展开更多
关键词 linear-differential cryptanalysis substitution permutation network advanced encryption standard (AES).
暂未订购 下载PDF
Automatic Search of Impossible Differentials and Zero-Correlation Linear Hulls for ARX Ciphers 认领 引用 被引量:5
4
作者 Kai Zhang Jie Guan Bin Hu 《China Communications》 SCIE CSCD 2018年第2期54-66,共13页
In lightweight cryptographic primitives, round functions with only simple operations XOR, modular addition and rotation are widely used nowadays. This kind of ciphers is called ARX ciphers. For ARX ciphers, impossible... In lightweight cryptographic primitives, round functions with only simple operations XOR, modular addition and rotation are widely used nowadays. This kind of ciphers is called ARX ciphers. For ARX ciphers, impossible differential cryptanalysis and zero-correlation linear cryptanalysis are among the most powerful attacks, and the key problems for these two attacks are discovering more and longer impossible differentials(IDs) and zero-correlation linear hulls(ZCLHs). However, finding new IDs and ZCLHs for ARX ciphers has been a manual work for a long time, which has been an obstacle in improving these two attacks. This paper proposes an automatic search method to improve the efficiency of finding new IDs and ZCLHs for ARX ciphers. In order to prove the efficiency of this new tool, we take HIGHT, LEA, SPECK three typical ARX algorithms as examples to explore their longer and new impossible differentials and zero-correlation linear hulls. To the best of our knowledge, this is the first application of automatic search method for ARX ciphers on finding new IDs and ZCLHs. For HIGHT, we find more 17 round IDs and multiple 17 round ZCLHs. This is the first discovery of 17 round ZCLHs for HIGHT. For LEA, we find extra four 10 round IDs and several 9 round ZCLHs. In the specification of LEA, the designers just identified three 10 round IDs and one 7round ZCLH. For SPECK, we find thousands of 6 round IDs and forty-four 6 round ZCLHs. Neither IDs nor ZCLHs of SPECK has been proposed before. The successful application of our new tool shows great potential in improving the impossible differential cryptanalysis and zero-correlation linear cryptanalysis on ARX ciphers.. 展开更多
关键词 automatic search tool impossibledifferential cryptanalysis zero-correlation lin-ear cryptanalysis ARX ciphers modes opera-tion
暂未订购 下载PDF
A Review of Existing 4-Bit Crypto S-Box Cryptanalysis Techniques and Two New Techniques with 4-Bit Boolean Functions for Cryptanalysis of 4-Bit Crypto S-Boxes 认领 引用 被引量:1
5
作者 Sankhanil Dey Ranjan Ghosh 《Advances in Pure Mathematics》 2018年第3期272-306,共35页
4-bit linear relations play an important role in cryptanalysis of 4-bit crypto S-boxes. 4-bit finite differences have also been a major part of cryptanalysis of 4-bit S-boxes. Existence of all 4-bit linear relations h... 4-bit linear relations play an important role in cryptanalysis of 4-bit crypto S-boxes. 4-bit finite differences have also been a major part of cryptanalysis of 4-bit S-boxes. Existence of all 4-bit linear relations have been counted for all of 16 input and 16 output 4-bit bit patterns of 4-bit Crypto S-boxes said as S-boxes has been reported in Linear Cryptanalysis of 4-bit S-boxes. Count of existing finite differences from each element of output S-boxes to distant output S-boxes have been noted in Differential Cryptanalysis of S-boxes. In this paper a brief review of these two cryptanalytic methods for 4-bit S-boxes has been introduced in a very lucid and conceptual manner. Two new analysis techniques, one to search for the existing linear approximations among the input vectors (IPVs) and output Boolean functions (BFs) of a particular S-box has also been introduced in this paper. The search is limited to find the existing linear relations or approximations in the contrary to count the number of existent linear relations among all 16, 4-bit input and output bit patterns within all possible linear approximations. Another is to find number of balanced BFs in difference output S-boxes. Better the number of Balanced BFs, Better the security. 展开更多
关键词 Linear Cryptanalysis Differential Cryptanalysis Substitution Boxes S-Boxes Cryptography Cryptanalysis
暂未订购 下载PDF
Algebraic Cryptanalysis of GOST Encryption Algorithm 认领 引用
6
作者 Ludmila Babenko Ekaterina Maro 《Journal of Computer and Communications》 2014年第4期10-17,共8页
This paper observes approaches to algebraic analysis of GOST 28147-89 encryption algorithm (also known as simply GOST), which is the basis of most secure information systems in Russia. The general idea of algebraic an... This paper observes approaches to algebraic analysis of GOST 28147-89 encryption algorithm (also known as simply GOST), which is the basis of most secure information systems in Russia. The general idea of algebraic analysis is based on the representation of initial encryption algorithm as a system of multivariate quadratic equations, which define relations between a secret key and a cipher text. Extended linearization method is evaluated as a method for solving the nonlinear sys- tem of equations. 展开更多
关键词 Encryption Algorithm GOST GOST S-Box Systems of Multivariate Quadratic Equations Algebraic Cryptanalysis Extended Linearization Method Gaussian Elimination
暂未订购 下载PDF
重新考察类RECTANGLE对称密码算法的设计 认领 引用
7
作者 丁天佑 张文涛 翁菁穗 《密码学报(中英文)》 CSCD 北大核心 2026年第2期283-309,共27页
轻量级分组密码算法TANGRAM以及认证加密与杂凑函数算法族KNOT基于RECTANGLE算法而设计,通过选取S盒与线性层移位参数,实现差分迹的最大差分概率与线性迹的最大线性相关性平方两项重要评估指标的最大化.但这些算法中的差分迹与线性迹中... 轻量级分组密码算法TANGRAM以及认证加密与杂凑函数算法族KNOT基于RECTANGLE算法而设计,通过选取S盒与线性层移位参数,实现差分迹的最大差分概率与线性迹的最大线性相关性平方两项重要评估指标的最大化.但这些算法中的差分迹与线性迹中总包含有迭代迹,且这样的迭代迹可能会形成聚集效应,可以用最小平均重量增长这一指标来衡量.本文利用平均重量增长能被快速计算的特性,重新考察了类RECTANGLE密码算法的S盒与线性层移位参数选取流程,将全部的移位参数选择纳入考虑,也将迭代迹聚集效应纳入考虑.并提出将TANGRAM与KNOT的S盒替换成RECTANGLE的S盒,能增强它们抵抗差分密码分析与线性密码分析的能力. 展开更多
关键词 轻量级对称密码算法 差分密码分析 线性密码分析 聚集效应
暂未订购 下载PDF
FR-FPE:有限基保留格式加密算法 认领 引用
8
作者 王小峰 叶军 +3 位作者 刘文正 孙兵 吴华晖 郭佳朴 《通信学报》 EI CSCD 北大核心 2026年第4期54-66,共13页
针对现有保留格式加密算法难以应对滑动关联及线性密码分析攻击且效率不高的问题,提出了有限基保留格式加密FR-FPE算法。通过设计基于CBC模式的参数向量加密机制和结构化调整参数全关联加密模型,有效抵御滑动关联及线性密码分析攻击。... 针对现有保留格式加密算法难以应对滑动关联及线性密码分析攻击且效率不高的问题,提出了有限基保留格式加密FR-FPE算法。通过设计基于CBC模式的参数向量加密机制和结构化调整参数全关联加密模型,有效抵御滑动关联及线性密码分析攻击。通过设计轻量化确定性加密结构,支持对不超过192 bit的明文和96 bit的调整参数进行加密,在保证算法与NIST FF1相同安全强度的同时,分组加密的调用次数比FF1减少45%(9次)。基于Game-Hopping博弈模型,给出了FR-FPE算法强伪随机置换(SPRP)安全性证明,并量化分析了算法抵御滑动关联及线性密码分析攻击的能力。实验结果表明,针对radix=36的数字字母混合数据集,FR-FPE的每秒加密次数比FF1平均高26.55%,加密数据吞吐率平均高21.25%。 展开更多
关键词 保留格式加密 滑动关联攻击 线性密码分析攻击 强伪随机置换
暂未订购 下载PDF
30轮LBC-IoT算法的线性分析 认领 引用
9
作者 李灵琛 陈佐甲 +1 位作者 韦永壮 叶涛 《通信学报》 EI CSCD 北大核心 2026年第2期209-218,共10页
为了评估LBC-IoT算法抵抗线性分析的能力,基于MILP自动化搜索技术,同时采用直接搜索和迭代线性逼近循环构建两种方法求解轮数最长的线性逼近集合,并在扩展轮数尽可能长的情况下得到每一条线性逼近的初始密钥猜测基。进一步结合最小猜测... 为了评估LBC-IoT算法抵抗线性分析的能力,基于MILP自动化搜索技术,同时采用直接搜索和迭代线性逼近循环构建两种方法求解轮数最长的线性逼近集合,并在扩展轮数尽可能长的情况下得到每一条线性逼近的初始密钥猜测基。进一步结合最小猜测基技术对初始密钥猜测基进行压缩,以此筛选出最优线性逼近进行密钥恢复攻击。结果表明,LBC-IoT算法共有6条线性偏差为2-15的23轮线性逼近,其中存在唯一一条最小猜测基仅为52 bit的最优线性逼近。基于该区分器向上和向下分别扩展3轮和4轮,首次对LBC-IoT算法发起了最长30轮的密钥恢复攻击。该攻击的数据、时间和存储复杂度分别为230个已知明文、277.9次30轮加密和252。相比已有结果,攻击轮数整体提升了4轮,导致LBC-IoT算法的安全冗余轮数不足7%,不建议用于实际的通信数据加密。 展开更多
关键词 轻量级分组密码 LBC-IoT算法 线性分析 最小猜测基
暂未订购 下载PDF
搜索最优差分和线性迹的高效方法:应用于NOEKEON和Serpent算法 认领 引用
10
作者 翁菁穗 张文涛 彭婷 《密码学报(中英文)》 CSCD 北大核心 2026年第1期80-96,共17页
抵御差分分析和线性分析的能力是评估对称密码算法安全性的两个核心指标.目前,已有多种自动化搜索工具可用于寻找密码算法的最优差分迹和最优线性迹.然而,当应用于线性层包含异或操作的密码算法时,这些工具通常效率不高或通用性不足.为... 抵御差分分析和线性分析的能力是评估对称密码算法安全性的两个核心指标.目前,已有多种自动化搜索工具可用于寻找密码算法的最优差分迹和最优线性迹.然而,当应用于线性层包含异或操作的密码算法时,这些工具通常效率不高或通用性不足.为解决这一问题,本文提出一种针对此类分组密码的高效通用搜索工具.通过记忆化迭代搜索策略,改进了基于搜索模式的Matsui算法.该策略充分利用了先前的搜索结果,显著减少了重复计算.整个搜索过程被划分为两个阶段:扩展搜索模式阶段和两轮模式搜索阶段.在扩展搜索模式阶段,利用密码的线性层性质和稳定掩码技术,加快了剪枝过程.在两轮模式搜索阶段,采用最窄点技术以减小初始搜索空间,并结合差分模式和线性掩码模式,进一步提升算法效率.应用改进后的工具评估NOEKEON和Serpent算法,均给出它们在差分分析和线性分析下最紧的安全界.对于NOEKEON算法,成功获得了至多9轮最优差分迹和至多16轮(全轮)最优线性迹.特别地,首次得到一个可用于差分攻击的概率为2-126的8轮最优差分迹.对于Serpent算法,获得了至多5轮最优差分迹和至多9轮最优线性迹,并首次证明了10轮Serpent的最大差分概率上界为2129,以及12轮Serpent的最大线性相关性上界为2-68. 展开更多
关键词 差分分析 线性分析 自动化搜索 NOEKEON算法 Serpent算法
暂未订购 下载PDF
对缩减轮SPECK改进的差分-线性分析 认领 引用
11
作者 张语晗 张蕾 吴文玲 《软件学报》 EI CSCD 北大核心 2026年第5期2274-2285,共12页
差分-线性分析是的一种组合类分析方法,已经被应用于许多对称密码的分析中.特别地,对于ARX类分组密码算法SPECK,差分-线性分析是评估其安全性的一种强有力的方式.在最新的差分-线性分析框架中,密码算法被分解为3部分:差分部分、中间部... 差分-线性分析是的一种组合类分析方法,已经被应用于许多对称密码的分析中.特别地,对于ARX类分组密码算法SPECK,差分-线性分析是评估其安全性的一种强有力的方式.在最新的差分-线性分析框架中,密码算法被分解为3部分:差分部分、中间部分和线性部分,其中差分部分、中间部分和线性部分分别包含高概率的差分特征,高相关性的差分-线性逼近和高相关性的线性逼近,组合3部分特征可以得到一个完整的差分-线性区分器.对于ARX类对称密码算法,在传统的差分-线性区分器的搜索过程中,通常是首先借助实验方法来计算得到中间部分一个高相关性的差分-线性逼近,然后再分别向前向后搜索线性特征和差分特征,但是该策略容易忽视掉一些好的差分-线性区分器.区别于传统的搜索算法,该算法结合高相关性的差分-线性逼近中差分部分和线性部分的特点,从高概率的差分特征和线性特征出发,给出一个差分-线性区分器搜索算法.将所提搜索算法应用于SPECK中,首次得到SPECK32的11轮差分-线性区分器和SPECK48的12轮差分-线性区分器.所提区分器都优于SPECK32和SPECK48目前已知最好的差分-线性区分器. 展开更多
关键词 密码分析 对称密码 差分-线性分析 SPECK 分组密码
暂未订购 下载PDF
分组密码算法的仿射线性密码分析 认领 引用
12
作者 曹文芹 张文涛 《信息安全学报》 CSCD 2026年第3期249-261,共13页
线性密码分析是分组密码算法重要的统计分析方法之一。自从20世纪90年代初Matsui提出线性密码分析以来,很多学者已经对线性密码分析及其推广的各种线性分析进行了大量的研究,辉煌的成果不计其数,其中多维线性密码分析就是一种极其重要... 线性密码分析是分组密码算法重要的统计分析方法之一。自从20世纪90年代初Matsui提出线性密码分析以来,很多学者已经对线性密码分析及其推广的各种线性分析进行了大量的研究,辉煌的成果不计其数,其中多维线性密码分析就是一种极其重要的研究成果。线性密码分析利用正确密钥和错误密钥下线性逼近的相关系数的平方服从具有不同期望值的Gamma分布来恢复密钥。多维线性密码分析使用了线性子空间中所有的非零线性逼近,通过组合多个Gamma分布来扩大正确密钥和错误密钥下容量的差异,从而提高了密钥恢复攻击的效率。而线性子空间中的线性逼近对容量的贡献大小不一样,贡献较小的线性逼近对提高密钥恢复攻击效率起的作用较小。为此,Nyberg提出了仿射线性密码分析,它是多维线性密码分析的一个新的变体。仿射线性密码分析舍弃了多维线性子空间中对容量贡献较小或者没有贡献的一半线性逼近,仅从保留的仿射子空间提取信息,构造了更有效的卡方检验统计量对分组密码进行攻击。为了进一步提高攻击的效率,Nyberg猜想舍弃仿射统计量中得分较小的项,利用剩余项仍可以构造服从卡方分布的统计检验统计量。本文利用统计手段证明了Nyberg猜想是正确的,并给出了该猜想的一个应用方法。最后,利用PRESENT和Serpent算法验证了Nyberg模型的有效性。对26轮PRESENT,利用Nyberg猜想进行了数据复杂度为261.5,时间复杂度为268.37的密钥恢复攻击;对27轮PRESENT,可以利用Nyberg猜想进行数据复杂度为263.25,时间复杂度为268.37的密钥恢复攻击。另外,分析了4轮Serpent算法仿射线性密码分析的数据复杂度。 展开更多
关键词 多维线性分析 仿射线性分析 PRESENT
暂未订购 下载PDF
轻量级分组密码INLEC的全轮积分分析 认领 引用
13
作者 余彬 刘文芬 +3 位作者 陈文 郭影 陆永灿 黄月华 《电子与信息学报》 EI CAS CSCD 北大核心 2026年第5期2259-2267,共9页
随着电信技术的快速发展,物联网设备得到日益普及,针对物联网设备的功耗、数据隐私和安全性等问题,许多轻量级密码算法给出了解决方案。为了应对数据传输过程中电池寿命和能源受限的问题,一种低能耗的轻量级分组密码INLEC被提出以减少... 随着电信技术的快速发展,物联网设备得到日益普及,针对物联网设备的功耗、数据隐私和安全性等问题,许多轻量级密码算法给出了解决方案。为了应对数据传输过程中电池寿命和能源受限的问题,一种低能耗的轻量级分组密码INLEC被提出以减少物联网设备中的数据泄露。该算法能有效抵抗差分、线性、不可能差分以及侧信道等多种密码分析技术,但尚未对其抵抗积分分析能力进行评估。为此,该文对其在积分分析下的安全性进行全面研究。利用单项式预测技术对INLEC算法进行混合整数线性规划(MILP)建模,首次得到了INLEC的9轮积分区分器。进一步结合扩散层的结构特性,扩展得到10轮积分区分器。在此基础上,利用部分和技术和多密钥猜测方法对算法进行14轮密钥恢复攻击,其数据复杂度为263选择明文,时间复杂度为289.843次14轮加密。分析结果表明,INLEC算法不足以抵抗积分分析。 展开更多
关键词 积分密码分析 单项式预测 INLEC 混合整数线性规划 物联网
暂未订购 下载PDF
基于神经网络的Simeck算法差分-线性分析 认领 引用
14
作者 卜予彤 沈璇 +1 位作者 孙兵 付佳韵 《网络空间安全科学学报》 CSCD 2026年第4期99-113,共15页
针对轻量级分组密码Simeck32/64算法,本文提出一种基于残差神经网络的差分-线性区分器构造方法,并基于该方法开展密钥恢复攻击研究。该方法融合差分分析与线性分析的技术优势,设计了同时包含密文对差分值与线性掩码分量的新型输入数据格... 针对轻量级分组密码Simeck32/64算法,本文提出一种基于残差神经网络的差分-线性区分器构造方法,并基于该方法开展密钥恢复攻击研究。该方法融合差分分析与线性分析的技术优势,设计了同时包含密文对差分值与线性掩码分量的新型输入数据格式,搭建深度残差一维卷积神经网络模型,用于捕捉密码算法多轮加密过程中产生的复杂统计偏差。通过聚合多组密文对构建模型输入样本,有效提升了模型对微弱统计特征的感知能力。相较于现有基于单一差分分析的神经网络区分器,该方法在7~10轮加密区间内,可依托更低的数据复杂度实现更高的区分准确率。基于所构建的差分-线性区分器,本文完成了9~13轮Simeck32/64算法的密钥恢复攻击,实验结果验证了该差分-线性分析方法应用于神经网络辅助密码分析的有效性与可行性。 展开更多
关键词 轻量级分组密码 Simeck算法 差分-线性分析 多层感知机 卷积神经网络 残差神经网络 密钥恢复攻击
暂未订购 下载PDF
Algebraic attacks on two kinds of special nonlinear filter generators 认领 引用
15
作者 杨文峰 Hu Yupu Qiu Hua 《High Technology Letters》 EI CAS 2012年第2期151-154,共4页
This letter proposes algebraic attacks on two kinds of nonlinear filter generators with symmetric Boolean functions as the filter fimctions. Different fxom the classical algebraic attacks, the proposed attacks take th... This letter proposes algebraic attacks on two kinds of nonlinear filter generators with symmetric Boolean functions as the filter fimctions. Different fxom the classical algebraic attacks, the proposed attacks take the advantage of the combinational property of a linear feedback shift register (LFSR) and the symmetric Boolean function to obtain a tow-degree algebraic relation, and hence the complexities of the proposed attacks are independent of the algebraic immunity (AI) of the filter functions. It is shown that improper combining of the LFSR with the filter function can make the filter generator suffer from algebraic attacks. As a result, the bits of the LFSR must be selected properly to input the filter function with large AI in order to withstand the proposed algebraic attacks. 展开更多
关键词 stream cipher linear feedback shift register (LFSR) Boolean function algebraic attack cryptanalysis
暂未订购 下载PDF
Improved Linear Cryptanalysis of CAST-256 认领 引用 被引量:2
16
作者 赵静远 王美琴 温隆 《Journal of Computer Science & Technology》 SCIE EI CSCD 2014年第6期1134-1139,共6页
CAST-256, a first-round AES (Advanced Encryption Standard) candidate, is designed based on CAST-128. It is a 48-round Generalized-Feistel-Network cipher with ]28-bit block accepting 128, 160, 192, 224 or 256 bits ke... CAST-256, a first-round AES (Advanced Encryption Standard) candidate, is designed based on CAST-128. It is a 48-round Generalized-Feistel-Network cipher with ]28-bit block accepting 128, 160, 192, 224 or 256 bits keys. Its S-boxes are non-surjective with 8-bit input and 32-bit output. Wang et al. identified a 21-round linear approximation and gave a key recovery attack on 24-round CAST-256. In ASIACRYPT 2012, Bogdanov et al. presented the multidimensional zero-correlation linear cryptanalysis of 28 rounds of CAST-256. By observing the property of the concatenation of forward quad-round and reverse quad-round and choosing the proper active round function, we construct a linear approximation of 26-round CAST-256 and recover partial key information on 32 rounds of CAST-256. Our result is the best attack according to the number of rounds for CAST-256 without weak-key assumption so far. 展开更多
关键词 CAST-256 linear cryptanalysis block cipher Generalized-Feistel-Network
暂未订购 下载PDF
Probability method for cryptanalysis of general multivariate modular linear equation 认领 引用 被引量:3
17
作者 ZHOU HaiJian LUO Ping +1 位作者 WANG DaoShun DAI YiQi 《Science in China(Series F)》 2009年第10期1792-1800,共9页
Finding the solution to a general multivariate modular linear equation plays an important role in cryptanalysis field. Earlier results show that obtaining a relatively short solution is possible in polynomial time. Ho... Finding the solution to a general multivariate modular linear equation plays an important role in cryptanalysis field. Earlier results show that obtaining a relatively short solution is possible in polynomial time. However, one problem arises here that if the equation has a short solution in given bounded range, the results outputted by earlier algorithms are often not the ones we are interested in. In this paper, we present a probability method based on lattice basis reduction to solve the problem. For a general multivariate modular linear equation with short solution in the given bounded range, the new method outputs this short solution in polynomial time, with a high probability. When the number of unknowns is not too large (smaller than 68), the probability is approximating 1. Experimental results show that Knapsack systems and Lu-Lee type systems are easily broken in polynomial time with this new method. 展开更多
关键词 public key cryptosystems cryptanalysis lattice basis reduction multivariate modular linear equation
Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers 认领 引用 被引量:1
18
作者 Wenqin Cao Wentao Zhang 《Cybersecurity》 EI CSCD 2022年第1期10-27,共18页
For block ciphers,Bogdanov et al.found that there are some linear approximations satisfying that their biases are deterministically invariant under key difference.This property is called key difference invariant bias.... For block ciphers,Bogdanov et al.found that there are some linear approximations satisfying that their biases are deterministically invariant under key difference.This property is called key difference invariant bias.Based on this property,Bogdanov et al.proposed a related-key statistical distinguisher and turned it into key-recovery attacks on LBlock and TWINE-128.In this paper,we propose a new related-key model by combining multidimensional linear cryptanalysis with key difference invariant bias.The main theoretical advantage is that our new model does not depend on statistical independence of linear approximations.We demonstrate our cryptanalysis technique by performing key recovery attacks on LBlock and TWINE-128.By using the relations of the involved round keys to reduce the number of guessed subkey bits.Moreover,the partial-compression technique is used to reduce the time complexity.We can recover the master key of LBlock up to 25 rounds with about 260.4distinct known plaintexts,278.85time complexity and 261bytes of memory requirements.Our attack can recover the master key of TWINE-128 up to 28 rounds with about 261.5distinct known plaintexts,2126.15time complexity and 261 bytes of memory requirements.The results are the currently best ones on cryptanalysis of LBlock and TWINE-128. 展开更多
关键词 Key-alternating cipher Key difference invariant bias Multidimensional linear cryptanalysis LBlock TWINE
超轻量级分组密码LiCi、LiCi-2和GRANULE的完美线性逼近 认领 引用
19
作者 严智广 李灵琛 韦永壮 《电子学报》 EI CAS CSCD 北大核心 2025年第5期1453-1459,共7页
LiCi、LiCi-2和GRANULE密码算法均为面向资源极端受限物联网环境的超轻量级分组密码算法,其加、解密速度快且易于软硬件实现,目前备受业界广泛关注.本文通过利用这些算法的线性结构特性,构造了多条绝对相关性为1的迭代(循环)完美线性逼... LiCi、LiCi-2和GRANULE密码算法均为面向资源极端受限物联网环境的超轻量级分组密码算法,其加、解密速度快且易于软硬件实现,目前备受业界广泛关注.本文通过利用这些算法的线性结构特性,构造了多条绝对相关性为1的迭代(循环)完美线性逼近,并由此设计出全轮的完美线性逼近(线性区分器),进而完全攻破了这些密码算法,即证实了全轮的LiCi、LiCi-2和GRANULE密码算法存在严重的设计缺陷. 展开更多
关键词 轻量级分组密码 线性密码分析 完美线性逼近 Feistel结构
暂未订购 下载PDF
Cryptanalysis of Public Key Cryptosystems Based on Non-Abelian Factorization Problems 认领 引用 被引量:4
20
作者 Jinhui Liu Aiwan Fan +3 位作者 Jianwei Jia Huanguo Zhang Houzhen Wang Shaowu Mao 《Tsinghua Science and Technology》 SCIE EI CAS CSCD 2016年第3期344-351,共8页
Advances in quantum computers threaten to break public-key cryptosystems (e.g., RSA, ECC, and EIGamal), based on the hardness of factoring or taking a discrete logarithm. However, no quantum algorithms have yet been... Advances in quantum computers threaten to break public-key cryptosystems (e.g., RSA, ECC, and EIGamal), based on the hardness of factoring or taking a discrete logarithm. However, no quantum algorithms have yet been found for solving certain mathematical problems in non-commutative algebraic structures. Recently, two novel public-key encryption schemes, BKT-B cryptosystem and BKT-FO cryptosystem, based on factorization problems have been proposed at Security and Communication Networks in 2013. In this paper we show that these two schemes are vulnerable to structural attacks and linearization equations attacks, and that they only require polynomial time complexity to obtain messages from associated public keys. We conduct a detailed analysis of the two attack methods and show corresponding algorithmic descriptions and efficiency analyses. In addition, we provide some improvement suggestions for the two public-key encryption schemes. 展开更多
关键词 cryptography post-quantum cryptography public key encryption cryptanalysis linear equations
暂未订购 下载PDF
上一页 1 2 5 下一页 到第
在线咨询 使用帮助 返回顶部 意见反馈