信息网络安全 ›› 2024, Vol. 24 ›› Issue (6): 948-958.doi: 10.3969/j.issn.1671-1122.2024.06.012

• 密码专题 • 上一篇    下一篇

CLEFIA动态密码结构的零相关线性区分器构造研究

沈霞民, 熊涛(), 李华, 沈璇   

  1. 国防科技大学信息通信学院,武汉 430010
  • 收稿日期:2024-03-05 出版日期:2024-06-10 发布日期:2024-07-05
  • 通讯作者: 熊涛 1010326252@qq.com
  • 作者简介:沈霞民(1993—),男,浙江,硕士研究生,主要研究方向为对称密码的设计与分析|熊涛(1990—),男,安徽,讲师,硕士,主要研究方向为无线通信安全|李华(1990—),男,四川,硕士研究生,主要研究方向为无线通信安全|沈璇(1990—),男,湖北,副教授,博士,主要研究方向为对称密码的设计与分析
  • 基金资助:
    国家自然科学基金(62002370);国家自然科学基金(62272470);国防科技大学科研计划项目基金(ZK21-36)

Research on the Construction of Zero-Correlation Linear Discriminator for CLEFIA Dynamic Cipher Structure

SHEN Xiamin, XIONG Tao(), LI Hua, SHEN Xuan   

  1. College of Information and Communication, National University of Defense Technology, Wuhan 430010, China
  • Received:2024-03-05 Online:2024-06-10 Published:2024-07-05

摘要:

随着分组密码应用研究的不断深入,研究者发现,“动态可变”分组密码设计可有效提升分组密码算法的应用灵活性和部署安全性。CLEFIA算法遵循“动态可变”思想,一些学者对CLEFIA算法的线性变换层加以改进,使得第6t(t≥1)轮中的扩散层可以从{0,1}4上的多个线性双射变换中任意选取。为分析评估CLEFIA动态密码结构的安全性能,文章主要采取零相关线性分析理论,利用中间相错技术和矩阵表示方法,分析构造CLEFIA动态密码结构的零相关线性区分器。研究证明,在轮函数为双射的前提条件下,CLEFIA动态密码结构动态线性层控制参数μi∈$F$2,(0≤i≤4)无论取何值,总存在8轮零相关线性区分器;当控制参数μ0=0时,存在9轮零相关线性区分器。

关键词: 分组密码, CLEFIA动态密码结构, 零相关线性分析, 中间相错技术, 矩阵表示

Abstract:

With the deepening of the research on block cipher application, the design of “dynamic variable” block cipher can effectively improve the application flexibility and deployment security of block cipher algorithm. CLEFIA algorithm follows the idea of “dynamic variable”, some scholars have improved the linear transformation layer of CLEFIA algorithm, so that the diffusion layer in the 6t(t≥1) round can be arbitrarily selected from the {0,1}4 multiple linear bijection transforms. In order to analyze and evaluate the security performance of CLEFIA dynamic cipher structure, this paper mainly adopted the theory of zero-correlation linear analysis, and used the miss-in-the-middle technique and matrix representation method to analyze the zero-correlation linear discriminator of CLEFIA dynamic cipher structure. The results show that under the condition that the wheel function is bijective, no matter what the control parameters μiF2,(0≤i≤4) of the dynamic linear layer of CLEFIA dynamic cipher structure are, there are always 8 rounds of zero-correlation linear discriminators. When controlling parameters μ0=0, there are 9 rounds of zero-correlation linear discriminators.

Key words: block cipher, CLEFIA dynamic cipher structure, zero correlation linear analysis, miss-in-the-middle technique, matrix representation

中图分类号: