Integral Cryptanalysis on Full MISTY1

被引:33
|
作者
Todo, Yosuke [1 ,2 ]
机构
[1] NTT Secure Platform Labs, Tokyo, Japan
[2] Kobe Univ, Kobe, Hyogo, Japan
关键词
MISTY1; Integral attack; Division property; ATTACK;
D O I
10.1007/s00145-016-9240-x
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
MISTY1 is a block cipher designed by Matsui in 1997. It was well evaluated and standardized by projects, such as CRYPTREC, ISO/IEC, and NESSIE. In this paper, we propose a key recovery attack on the full MISTY1, i.e., we show that 8-round MISTY1 with 5 FL layers does not have 128-bit security. Many attacks against MISTY1 have been proposed, but there is no attack against the full MISTY1. Therefore, our attack is the first cryptanalysis against the full MISTY1. We construct a new integral characteristic by using the propagation characteristic of the division property, which was proposed in EUROCRYPT 2015. We first improve the division property by optimizing the division property for a public S-box and then construct a 6-round integral characteristic on MISTY1. Finally, we recover the secret key of the full MISTY1 with 2(63.58) chosen plaintexts and 2(121) time complexity. Moreover, if we use 2(63.994) chosen plaintexts, the time complexity for our attack is reduced to 2(108.3.) Note that our cryptanalysis is a theoretical attack. Therefore, the practical use of MISTY1 will not be affected by our attack.
引用
收藏
页码:920 / 959
页数:40
相关论文
共 50 条
  • [1] Integral Cryptanalysis on Full MISTY1
    Todo, Yosuke
    ADVANCES IN CRYPTOLOGY, PT I, 2015, 9215 : 413 - 432
  • [2] Integral Cryptanalysis on Full MISTY1
    Yosuke Todo
    Journal of Cryptology, 2017, 30 : 920 - 959
  • [3] Improved cryptanalysis of MISTY1
    Kühn, U
    FAST SOFTWARE ENCRYPTION (REVISED PAPERS), 2002, 2365 : 61 - 75
  • [4] Improved Integral Attacks on MISTY1
    Sun, Xiaorui
    Lai, Xuejia
    SELECTED AREAS IN CRYPTOGRAPHY, 2009, 5867 : 266 - 280
  • [5] A 270 Attack on the Full MISTY1
    Bar-On, Achiya
    Keller, Nathan
    ADVANCES IN CRYPTOLOGY - CRYPTO 2016, PT I, 2016, 9814 : 435 - 456
  • [6] Weak keys of the full MISTY1 block cipher for related-key amplified boomerang cryptanalysis
    Lu, Jiqiang
    Yap, Wun-She
    Wei, Yongzhuang
    IET INFORMATION SECURITY, 2018, 12 (05) : 389 - 397
  • [7] Improving the efficiency of impossible differential cryptanalysis of reduced Camellia and MISTY1
    Lu, Jiqiang
    Kim, Jongsung
    Keller, Nathan
    Dunkelman, Orr
    TOPICS IN CRYPTOLOGY - CT-RSA 2008, PROCEEDINGS, 2008, 4964 : 370 - +
  • [8] Weak Keys of the Full MISTY1 Recovered in Practical Time
    Taga, Bungo
    Ito, Norimitsu
    Okano, Takako
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2024, 2024, 14977 : 65 - 81
  • [9] Security analysis of MISTY1
    Tanaka, Hidema
    Hatano, Yasuo
    Sugio, Nobuyuki
    Kaneko, Toshinobu
    INFORMATION SECURITY APPLICATIONS, 2007, 4867 : 215 - +
  • [10] Finding Higher Order Differentials of MISTY1
    Tsunoo, Yukiyasu
    Saito, Teruo
    Kawabata, Takeshi
    Nakagawa, Hirokatsu
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2012, E95A (06) : 1049 - 1055