Integral Cryptanalysis on Full MISTY1

被引:33
|
作者
Todo, Yosuke [1 ,2 ]
机构
[1] NTT Secure Platform Labs, Tokyo, Japan
[2] Kobe Univ, Kobe, Hyogo, Japan
关键词
MISTY1; Integral attack; Division property; ATTACK;
D O I
10.1007/s00145-016-9240-x
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
MISTY1 is a block cipher designed by Matsui in 1997. It was well evaluated and standardized by projects, such as CRYPTREC, ISO/IEC, and NESSIE. In this paper, we propose a key recovery attack on the full MISTY1, i.e., we show that 8-round MISTY1 with 5 FL layers does not have 128-bit security. Many attacks against MISTY1 have been proposed, but there is no attack against the full MISTY1. Therefore, our attack is the first cryptanalysis against the full MISTY1. We construct a new integral characteristic by using the propagation characteristic of the division property, which was proposed in EUROCRYPT 2015. We first improve the division property by optimizing the division property for a public S-box and then construct a 6-round integral characteristic on MISTY1. Finally, we recover the secret key of the full MISTY1 with 2(63.58) chosen plaintexts and 2(121) time complexity. Moreover, if we use 2(63.994) chosen plaintexts, the time complexity for our attack is reduced to 2(108.3.) Note that our cryptanalysis is a theoretical attack. Therefore, the practical use of MISTY1 will not be affected by our attack.
引用
收藏
页码:920 / 959
页数:40
相关论文
共 50 条
  • [41] 八轮MISTY1算法的相关密钥扩大飞来去器攻击
    陈少真
    戴艺滨
    国防科技大学学报, 2012, 34 (02) : 29 - 33
  • [42] Integral cryptanalysis
    Knudsen, L
    Wagner, D
    FAST SOFTWARE ENCRYPTION (REVISED PAPERS), 2002, 2365 : 112 - 127
  • [43] Integral Cryptanalysis on Simeck
    Zhang, Kai
    Guan, Jie
    Hu, Bin
    Lin, Dongdai
    2016 SIXTH INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND TECHNOLOGY (ICIST), 2016, : 216 - 222
  • [44] Ultrametric Integral Cryptanalysis
    Beyne, Tim
    Verbauwhede, Michiel
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2024, PT VII, 2025, 15490 : 392 - 423
  • [45] Integral Cryptanalysis of ARIA
    Li, Ping
    Sun, Bing
    Li, Chao
    INFORMATION SECURITY AND CRYPTOLOGY, 2010, 6151 : 1 - 14
  • [46] Integral cryptanalysis of SAFER
    Hu, YP
    Zhang, YQ
    Xiao, GZ
    ELECTRONICS LETTERS, 1999, 35 (17) : 1458 - 1459
  • [47] Cryptanalysis of Full Sprout
    Lallemand, Virginie
    Naya-Plasencia, Maria
    ADVANCES IN CRYPTOLOGY, PT I, 2015, 9215 : 663 - 682
  • [48] Integral Cryptanalysis and Impossible Differential Cryptanalysis of the μ2 Algorithm
    Hu Bin
    Zhang Guixian
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2022, 44 (09) : 3335 - 3342
  • [49] Biclique Cryptanalysis of the Full AES
    Bogdanov, Audrey
    Khovratovich, Dmitry
    Rechberger, Christian
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2011, 2011, 7073 : 344 - +
  • [50] SIGABA: Cryptanalysis of the full keyspace
    Stamp, Mark
    Chan, Wing On
    CRYPTOLOGIA, 2007, 31 (03) : 201 - 222