信息网络安全 ›› 2021, Vol. 21 ›› Issue (8): 43-51.doi: 10.3969/j.issn.1671-1122.2021.08.006

• 技术研究 • 上一篇    下一篇

Mysterion算法的不可能差分分析

杨云霄1, 沈璇2(), 孙兵1,3   

  1. 1.国防科技大学文理学院,长沙 410073
    2.国防科技大学信息通信学院,武汉 430010
    3.商用密码理论与技术创新湖南省工程研究中心,长沙 410000
  • 收稿日期:2021-04-20 出版日期:2021-08-10 发布日期:2021-09-01
  • 通讯作者: 沈璇 E-mail:shenxuan_08@163.com
  • 作者简介:杨云霄(1996—),男,湖北,硕士研究生,主要研究方向为分组密码的分析|沈璇(1990—),男,湖北,讲师,博士,主要研究方向为分组密码的分析|孙兵(1981—),男,江苏,副教授,博士,主要研究方向为对称密码的设计与分析
  • 基金资助:
    国家自然科学基金(61772545);国家自然科学基金(62002370);湖南省自然科学基金(2020JJ5667)

Impossible Differential Cryptanalysis of Mysterion

YANG Yunxiao1, SHEN Xuan2(), SUN Bing1,3   

  1. 1. College of Liberal Arts and Sciences, National University of Defense Technology, Changsha 410073, China
    2. College of Information and Communication, National University of Defense Technology, Wuhan 430010, China
    3. Hunan Engineering Research Center of Commercial Cryptography Theory and Technology Innovation,Changsha 410000, China
  • Received:2021-04-20 Online:2021-08-10 Published:2021-09-01
  • Contact: SHEN Xuan E-mail:shenxuan_08@163.com

摘要:

Mysterion算法是XLS设计策略的具体实例,该算法的主要目的是改进LS设计策略,在不影响实现效率的前提下提升LS设计策略的安全性。文章采用不可能差分分析方法对Mysterion算法进行安全性分析,首先证明了Mysterion算法的结构不可能差分轮数最长为4轮,然后利用S盒的信息,突破了Mysterion的结构不可能差分上界,通过优化搜索算法得到5轮的算法不可能差分。Mysterion算法的最大不可能差分轮数比LS设计策略的代表算法Robin算法多1轮,从不可能差分的角度证明了XLS设计策略的安全性要弱于LS设计策略。

关键词: 分组密码, XLS设计策略, 不可能差分分析

Abstract:

The Mysterion block cipher is a specific example of the XLS-designs, the main purpose of this algorithm is to improve the LS-designs and enhance the security of LS design strategy without affecting the implementation efficiency. Impossible differential cryptanalysis is applied to analyze Mysterion. Firstly, it proves that the truncated impossible differential of the Mysterion algorithm is upper bounded by 4 rounds. Then, using the information of the S-box breaks through the upper bound of truncated impossible differential of Mysterion and manages to get 5-round impossible differential. The Mysterion’s maximum round of impossible differential is one more than the Robin algorithm, which is the representative algorithm of LS-designs. From the perspective of impossible differential, the security of XLS-designs is weaker than LS-designs.

Key words: block cipher, XLS-designs, impossible differential cryptanalysis

中图分类号: