收稿日期: 2001-04-29
网络出版日期: 2001-03-10
基金资助
973资助项目(G1999035802);国家自然科学基金跨学科重点资助项目(199931010)
On E2 and Camellia Block Cipher
Received date: 2001-04-29
Online published: 2001-03-10
对NTT公司近两年先后推出的分组密码算法E2和Camellia的特点及设计技巧进行了详细讨论.首先,指出Camellia的FL和FL- 1 函数的特点,利用此可以对Camellia进行中间相遇攻击 ;其次讨论E2和Camellia变形的安全性.结果显示如果采用一个S盒,则截断差分密码分析对 10轮的Camellia 构成威胁 ;而设计者称10轮Camellia对截断差分密码分析是免疫的,这说明采用 4个不同的S盒对Camellia的安全性起到很重要的作用.另一结果显示截断差分密码分析对 1 2轮E2 构成威胁,这反映了扩散层P选取不但要求它的分支数,而且应尽力减少它的循环差分特征
吴文玲 . 关于E2和Camllia密码算法[J]. 中国科学院大学学报, 2001 , 18(2) : 181 -185 . DOI: 10.7523/j.issn.2095-6134.2001.2.017
E2 and Camellia were developed by NTT in recent two years,which reflect the design level of block cipher in Japan.We discuss their speciality and design skill.Firstly,we point out the property of FL and FL -1 which could be used to attack Camellia by meet-in-middle.Next we analyze the variant of Camellia-Camellia *,and the result show that truncated differential cryptanalysis threaten the security of the 10-round Camellia *.Therefore it is important using different S-boxes in Camellia.Finally we analyze the variant of E2-E2 *,and the result show that truncated differential cryptanalysis threaten the security of the 12-round E2 *.So the construction of P is important in the design of block cipher.
Key words: differential truncated; differential cryptanalysis; block cipher
1 N T T-Nippon T elegraph and Telephone Corporation :E2 :Ef ficient Encryption A lgorit hm.htt p :// info.isl.ntt.co.jp/ e2
2 K aoki, T Ichikaw a, M K anda, M M at sui, S M oriai, J Nakajima, T Tokita.Specif icat ion of Camellia-a 128-bit Block Ci pher.SAC′2000, Sev-enth Annual Workshop on Select ed A reas in C rypt ography, 2000.14 ~ 15
3 M K anda.Pract ical Secu rit y Evaluat ion A gainst Di ff erent ial and Linear A t tacks for Feist el Ciphers w it h S PN Round Function.SA C′2000.Seventh A nnual W orkshop on S elected Areas in Cryptography, 2000.14 ~ 15
4 M M atsui, T Tokit a.Cryptanalysi s of a Reduced Version of the Block Cipher E2.Fast S of tw are Encryption-6 thInt ernat ional Workshop, FSE′99, Lectu re N otes in Computer Sci ence 1636, 1999.71 ~ 80
5 S M oriai, M S ugi ta, K A oki, M K anda.S ecurity of E2 A gainst T runcated Dif ferential Cryptanalysi s.Select ed Areas in Crypt ography, 6 thAn-nual Internati onal Workshop, SA C′99, Lect ure N otes in Comput er S cience 1758, 2000.106 ~ 117
6 L R K nudsen.Truncat ed and Higher O rder Dif ferentials.Fast Sof tw are Encrypti on-Second International Workshop, Lect ure N ot es in Com-puter Science 1008, 1995.196 ~ 211
/
| 〈 |
|
〉 |