欢迎访问中国科学院大学学报,今天是

中国科学院大学学报 ›› 2001, Vol. 18 ›› Issue (2): 181-185.DOI: 10.7523/j.issn.2095-6134.2001.2.017

• 研究简报 • 上一篇    下一篇

关于E2和Camllia密码算法

吴文玲1,2   

  1. 1. 中国科学院软件研究所信息安全国家重点实验室, 北京 100080;
    2. 中国科学院信息安全技术工程研究中心, 北京 100080
  • 收稿日期:2001-04-29 发布日期:2001-03-10
  • 作者简介:吴文玲,女,1966年8月生,副研究员,博士
  • 基金资助:

    973资助项目(G1999035802);国家自然科学基金跨学科重点资助项目(199931010)

On E2 and Camellia Block Cipher

Wu Wenling1,2   

  1. 1. State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences;
    2. Engineering Research Center of Information Security Technology, Chinese Academy of Sciences, Beijing 100080
  • Received:2001-04-29 Published:2001-03-10

摘要:

对NTT公司近两年先后推出的分组密码算法E2和Camellia的特点及设计技巧进行了详细讨论.首先,指出Camellia的FL和FL- 1 函数的特点,利用此可以对Camellia进行中间相遇攻击 ;其次讨论E2和Camellia变形的安全性.结果显示如果采用一个S盒,则截断差分密码分析对 10轮的Camellia 构成威胁 ;而设计者称10轮Camellia对截断差分密码分析是免疫的,这说明采用 4个不同的S盒对Camellia的安全性起到很重要的作用.另一结果显示截断差分密码分析对 1 2轮E2 构成威胁,这反映了扩散层P选取不但要求它的分支数,而且应尽力减少它的循环差分特征

关键词: 差分, 截断差分密码分析, 分组密码

Abstract:

E2 and Camellia were developed by NTT in recent two years,which reflect the design level of block cipher in Japan.We discuss their speciality and design skill.Firstly,we point out the property of FL and FL -1 which could be used to attack Camellia by meet-in-middle.Next we analyze the variant of Camellia-Camellia *,and the result show that truncated differential cryptanalysis threaten the security of the 10-round Camellia *.Therefore it is important using different S-boxes in Camellia.Finally we analyze the variant of E2-E2 *,and the result show that truncated differential cryptanalysis threaten the security of the 12-round E2 *.So the construction of P is important in the design of block cipher.

Key words: differential truncated, differential cryptanalysis, block cipher

中图分类号: