Integral Cryptanalysis on Full MISTY1

被引:33
|
作者
Todo, Yosuke [1 ,2 ]
机构
[1] NTT Secure Platform Labs, Tokyo, Japan
[2] Kobe Univ, Kobe, Hyogo, Japan
关键词
MISTY1; Integral attack; Division property; ATTACK;
D O I
10.1007/s00145-016-9240-x
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
MISTY1 is a block cipher designed by Matsui in 1997. It was well evaluated and standardized by projects, such as CRYPTREC, ISO/IEC, and NESSIE. In this paper, we propose a key recovery attack on the full MISTY1, i.e., we show that 8-round MISTY1 with 5 FL layers does not have 128-bit security. Many attacks against MISTY1 have been proposed, but there is no attack against the full MISTY1. Therefore, our attack is the first cryptanalysis against the full MISTY1. We construct a new integral characteristic by using the propagation characteristic of the division property, which was proposed in EUROCRYPT 2015. We first improve the division property by optimizing the division property for a public S-box and then construct a 6-round integral characteristic on MISTY1. Finally, we recover the secret key of the full MISTY1 with 2(63.58) chosen plaintexts and 2(121) time complexity. Moreover, if we use 2(63.994) chosen plaintexts, the time complexity for our attack is reduced to 2(108.3.) Note that our cryptanalysis is a theoretical attack. Therefore, the practical use of MISTY1 will not be affected by our attack.
引用
收藏
页码:920 / 959
页数:40
相关论文
共 50 条
  • [21] On the dynamic reconfigurable implementations of MISTY1 and KASUMI block ciphers
    Jiexian, Huang
    Khizar, Yasir
    Ali, Zain Anwar
    Hasan, Raza
    Pathan, Muhammad Salman
    PLOS ONE, 2023, 18 (09):
  • [22] Practical-time attacks against reduced variants of MISTY1
    Dunkelman, Orr
    Keller, Nathan
    DESIGNS CODES AND CRYPTOGRAPHY, 2015, 76 (03) : 601 - 627
  • [23] Practical-time attacks against reduced variants of MISTY1
    Computer Science Department, University of Haifa, Haifa
    31905, Israel
    不详
    52900, Israel
    Des Codes Cryptography, 3 (601-627):
  • [24] MISTY1算法变形体的滑动攻击
    戴艺滨
    陈少真
    信息工程大学学报, 2012, 13 (02) : 141 - 145+150
  • [25] Higher Order Differential Attacks on Reduced-Round MISTY1
    Tsunoo, Yukiyasu
    Saito, Teruo
    Shigeri, Maki
    Kawabata, Takeshi
    INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2008, 2009, 5461 : 415 - +
  • [26] Practical-time attacks against reduced variants of MISTY1
    Orr Dunkelman
    Nathan Keller
    Designs, Codes and Cryptography, 2015, 76 : 601 - 627
  • [27] Area-Efficient Hardware Architectures of MISTY1 Block Cipher
    Yasir
    Wu, Ning
    Chen, Xin
    Yahya, Muhammad Rehan
    RADIOENGINEERING, 2018, 27 (02) : 541 - 548
  • [28] A time and area efficient hardware implementation of the misty1 block cipher
    Kitsos, P
    Koufopavlou, O
    Proceedings of the 46th IEEE International Midwest Symposium on Circuits & Systems, Vols 1-3, 2003, : 794 - 797
  • [29] Higher Order Differential Attack on 6-Round MISTY1
    Tsunoo, Yukiyasu
    Saito, Teruo
    Nakashima, Hiroki
    Shigeri, Maki
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2009, E92A (01) : 3 - 10
  • [30] (Quantum) Cryptanalysis of Misty Schemes
    Gouget, Aline
    Patarin, Jacques
    Toulemonde, Ambre
    INFORMATION SECURITY AND CRYPTOLOGY, ICISC 2020, 2021, 12593 : 43 - 57