Multidimensional Linear Cryptanalysis

被引:0
|
作者
Miia Hermelin
Joo Yeon Cho
Kaisa Nyberg
机构
[1] Finnish Defence Forces,
[2] ADVA Optical Networking,undefined
[3] Aalto University,undefined
来源
Journal of Cryptology | 2019年 / 32卷
关键词
Linear cryptanalysis; Multidimensional linear approximation; Key recovery; Matsui’s Algorithm 1; Matsui’s Algorithm 2; Goodness of fit; Key ranking; Advantage;
D O I
暂无
中图分类号
学科分类号
摘要
Linear cryptanalysis introduced by Matsui is a statistical attack which exploits a binary linear relation between plaintext, ciphertext and key, either in Algorithm 1 for recovering one bit of information of the secret key of a block cipher, or in Algorithm 2 for ranking candidate values for a part of the key. The statistical model is based on the expected and observed bias of a single binary value. Multiple linear approximations have been used with the goal to make the linear attack more efficient. More bits of information of the key can potentially be recovered possibly using less data. But then also more elaborated statistical models are needed to capture the joint behaviour of several not necessarily independent binary variables. Also more options are available for generalising the statistics of a single variable to several variables. The multidimensional extension of linear cryptanalysis to be introduced in this paper considers using multiple linear approximations that form a linear subspace. Different extensions of Algorithm 1 and Algorithm 2 will be presented and studied. The methods will be based on known statistical tools such as goodness-of-fit test and log-likelihood ratio. The efficiency of the different methods will be measured and compared in theory and experiments using the concept of advantage introduced by Selçuk. The block cipher Serpent with a reduced number of rounds will be used as test bed. The multidimensional linear cryptanalysis will also be compared with previous methods that use biasedness of multiple linear approximations. It will be shown in the simulations that the multidimensional method is potentially more powerful. Its main theoretical advantage is that the statistical model can be given without the assumption about statistical independence of the linear approximations.
引用
收藏
页码:1 / 34
页数:33
相关论文
共 50 条
  • [1] Multidimensional Linear Cryptanalysis
    Hermelin, Miia
    Cho, Joo Yeon
    Nyberg, Kaisa
    JOURNAL OF CRYPTOLOGY, 2019, 32 (01) : 1 - 34
  • [2] On Multidimensional Linear Cryptanalysis
    Nguyen, Phuong Ha
    Wei, Lei
    Wang, Huaxiong
    Ling, San
    INFORMATION SECURITY AND PRIVACY, 2010, 6168 : 37 - 52
  • [3] Separable Statistics and Multidimensional Linear Cryptanalysis
    Fauskanger, Stian
    Semaev, Igor
    IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY, 2018, 2018 (02) : 79 - 110
  • [4] Multidimensional Linear Cryptanalysis of Feistel Ciphers
    Ozdemir, Betuel Askin
    Beyne, Tim
    Rijmen, Vincent
    IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY, 2023, 2023 (04) : 1 - 27
  • [5] Improving the Algorithm 2 in Multidimensional Linear Cryptanalysis
    Phuong Ha Nguyen
    Wu, Hongjun
    Wang, Huaxiong
    INFORMATION SECURITY AND PRIVACY, 2011, 6812 : 61 - 74
  • [6] Multidimensional linear cryptanalysis of reduced round Serpent
    Hermelin, Miia
    Cho, Joo Yeon
    Nyberg, Kaisa
    INFORMATION SECURITY AND PRIVACY, 2008, 5107 : 203 - 215
  • [7] Evolutionary cryptography against multidimensional linear cryptanalysis
    HuanGuo Zhang
    ChunLei Li
    Ming Tang
    Science China Information Sciences, 2011, 54 : 2565 - 2577
  • [8] Evolutionary cryptography against multidimensional linear cryptanalysis
    ZHANG HuanGuo 1
    2 Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education of China
    ScienceChina(InformationSciences), 2011, 54 (12) : 2585 - 2597
  • [9] Evolutionary cryptography against multidimensional linear cryptanalysis
    Zhang HuanGuo
    Li ChunLei
    Tang Ming
    SCIENCE CHINA-INFORMATION SCIENCES, 2011, 54 (12) : 2565 - 2577
  • [10] POSTER: Generic Multidimensional Linear Cryptanalysis of Feistel Ciphers
    Ozdemir, Betul Askin
    Beyne, Tim
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3621 - 3623