通信学报2024,Vol.45Issue(11) :106-113.DOI:10.11959/j.issn.1000-436x.2024196

基于矩阵方法的减轮μ2算法不可能差分分析

Impossible differential cryptanalysis of reduced-round μ2 algorithm based on matrix method

杜小妮 余恬 贾美纯 梁丽芳
通信学报2024,Vol.45Issue(11) :106-113.DOI:10.11959/j.issn.1000-436x.2024196

基于矩阵方法的减轮μ2算法不可能差分分析

Impossible differential cryptanalysis of reduced-round μ2 algorithm based on matrix method

杜小妮 1余恬 2贾美纯 2梁丽芳2
扫码查看

作者信息

  • 1. 西北师范大学数学与统计学院,甘肃 兰州 730070;西北师范大学密码技术与数据分析重点实验室,甘肃 兰州 730070
  • 2. 西北师范大学数学与统计学院,甘肃 兰州 730070
  • 折叠

摘要

为了评估μ2算法在不可能差分分析方面的安全性,首先基于矩阵方法,结合中间相错技术构造了μ2算法的9轮不可能差分区分器.其次在该区分器的基础上分别向前和向后扩展2轮,利用密钥桥技术,对μ2算法进行了13轮密钥恢复攻击.研究结果表明,该攻击可恢复45 bit主密钥,数据复杂度为242.5个选择明文,时间复杂度为265.3次13轮算法加密.相比之前的研究结果,该研究实现了最长的攻击轮数,且数据复杂度显著降低.

Abstract

To evaluate the security of μ2 algorithm in impossible differential cryptanalysis,a 9-round impossible differen-tial distinguisher of μ2 algorithm was constructed based on matrix method and meet-in-the middle technique firstly.Then,with the utilization of key-bridge technique,a 13-round key recovery attack was presented to μ2 algorithm by expanding the 9-round distinguisher forward and backward 2 rounds,respectively.The results show that the master key can be re-covered 45 bit in the attack,the data complexity of plaintexts is 242.5,and the time complexity of 13 rounds of algorithm encryptions is 265.3.Compared with the previous research,the study achieves the longest attack rounds,and the data com-plexity is effectively reduced.

关键词

轻量级分组密码/μ2算法/不可能差分分析/矩阵方法

Key words

lightweight block cipher/μ2 algorithm/impossible differential cryptanalysis/matrix method

引用本文复制引用

出版年

2024
通信学报
中国通信学会

通信学报

CSTPCDCSCD北大核心
影响因子:1.265
ISSN:1000-436X
段落导航相关论文