Impossible Differential Cryptanalysis of 16/18-Round Khudra

被引:0
|
作者
Karakoc, Ferhat [1 ]
Sagdicoglu, Oznur Mut [1 ]
Gonen, Mehmet Emin [1 ,2 ]
Ersoy, Oguzhan [3 ]
机构
[1] TUBITAK BILGEM UEKAE, PK 74, TR-41470 Gebze, Kocaeli, Turkey
[2] Gebze Tech Univ, Gebze, Kocaeli, Turkey
[3] Bogazici Univ, Istanbul, Turkey
关键词
Khudra; Generalized feistel structure; Lightweight; Impossible differential cryptanalysis; LIGHTWEIGHT BLOCK CIPHER;
D O I
10.1007/978-3-319-55714-4_3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Khudra is a recently proposed lightweight block cipher specifically dedicated for Field Programmable Gate Arrays (FPGAs) implementation. It is a 4-branch type-2 generalized Feistel structure (GFS) of 18 rounds with 64-bit block size and 80-bit security margin. This paper studies the security of Khudra against impossible differential cryptanalysis. In the single-key scenario, the best impossible differential attack given by the designers works for 11 rounds with 2(57) chosen plaintexts and 2(61) encryptions. In this paper, by exploiting the structure of Khudra and the redundancy in its key schedule, we significantly improve previously known results. First, we propose an impossible differential attack on 14-round Khudra with 2(54.06) chosen plaintexts, 2(50.26) encryptions and 2(49) memory. Then, we extend the attack by including pre-whitening keys with 2(59.03) known plaintexts, 2(67.06) time and 2(59.03) memory complexities. Finally, we present an impossible differential attack against 16-round Khudra where whitening-keys are omitted. The 16-round attack requires 2(49.58) chosen plaintexts, 2(79.26) encryptions and 2(64) memory. To the best of our knowledge, these attacks are the best known attacks in the single-key scenario.
引用
收藏
页码:33 / 44
页数:12
相关论文
共 50 条
  • [1] Differential Cryptanalysis of 18-Round PRIDE
    Lallemand, Virginie
    Rasoolzadeh, Shahram
    PROGRESS IN CRYPTOLOGY - INDOCRYPT 2017, 2017, 10698 : 126 - 146
  • [2] Impossible differential cryptanalysis of reduced round XTEA and TEA
    Moon, D
    Hwang, KD
    Lee, W
    Lee, S
    Lim, JG
    FAST SOFTWARE ENCRYPTION (REVISED PAPERS), 2002, 2365 : 49 - 60
  • [3] Impossible Differential Cryptanalysis of Reduced-Round SKINNY
    Tolba, Mohamed
    Abdelkhalek, Ahmed
    Youssef, Amr M.
    PROGRESS IN CRYPTOLOGY - AFRICACRYPT 2017, 2017, 10239 : 117 - 134
  • [4] Impossible Differential Cryptanalysis on Reduced-Round PRINCEcore
    Zhang, Li
    Wu, Wenling
    Mao, Yongxia
    INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2022, 2023, 13849 : 61 - 77
  • [5] Multiple impossible differential cryptanalysis of reduced-round NBC
    Liang, Lifang
    Du, Xiaoni
    CRYPTOLOGIA, 2024,
  • [6] Impossible differential cryptanalysis of reduced-round ARIA and Camellia
    Wu, Wen-Ling
    Zhang, Wen-Tao
    Feng, Deng-Guo
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2007, 22 (03) : 449 - 456
  • [7] Impossible Differential Cryptanalysis of Reduced-Round ARIA and Camellia
    吴文玲
    张文涛
    冯登国
    Journal of Computer Science & Technology, 2007, (03) : 449 - 456
  • [8] New Impossible Differential Cryptanalysis of Reduced-Round Camellia
    Li, Leibo
    Chen, Jiazhe
    Jia, Keting
    CRYPTOLOGY AND NETWORK SECURITY, 2011, 7092 : 26 - +
  • [9] Impossible Differential Cryptanalysis of reduced-round TEA and XTEA
    Hajari, Masroor
    Azimi, Seyyed Arash
    Aghdaie, Poorya
    Salmasizadeh, Mahmoud
    Aref, Mohammad Reza
    2015 12TH INTERNATIONAL IRANIAN SOCIETY OF CRYPTOLOGY CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2015, : 58 - 63
  • [10] Impossible Differential Cryptanalysis of Reduced-Round ARIA and Camellia
    Wen-Ling Wu
    Wen-Tao Zhang
    Deng-Guo Feng
    Journal of Computer Science and Technology, 2007, 22 : 449 - 456