Related-key attacks on DDP based ciphers: CIKS-128 and CIKS-128H

Y Ko, C Lee, S Hong, J Sung, S Lee - Progress in Cryptology-INDOCRYPT …, 2005 - Springer
Progress in Cryptology-INDOCRYPT 2004: 5th International Conference on …, 2005Springer
Abstract CIKS-128 and CIKS-128H are 128-bit block ciphers with a 256-bit key sizes based
on data-dependent operations, respectively. They are also fast hardware-oriented ciphers
and improvements of block cipher CIKS-1 introduced in [14]. This paper presents related-key
differential attacks on full-round CIKS-128 and CIKS-128H. In result, using full-round related-
key differential characteristics with probability 2−− 36 and 2−− 35.4, these attacks can
recover the partial subkey bits for CIKS-128 and CIKS-128H with about 2 40 plaintexts …
Abstract
CIKS-128 and CIKS-128H are 128-bit block ciphers with a 256-bit key sizes based on data-dependent operations, respectively. They are also fast hardware-oriented ciphers and improvements of block cipher CIKS-1 introduced in [14]. This paper presents related-key differential attacks on full-round CIKS-128 and CIKS-128H. In result, using full-round related-key differential characteristics with probability 2− − 36 and 2− − 35.4, these attacks can recover the partial subkey bits for CIKS-128 and CIKS-128H with about 240 plaintexts, respectively. These works suggests that the greatest possible care has to be taken when proposing improvements of the existing block ciphers.
Springer
以上显示的是最相近的搜索结果。 查看全部搜索结果