分块对称密码的全微分和线性壳的极大值分布(IJCNIS-V6-N1-2)

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

I.J.ComputerNetworkandInformationSecurity,2014,1,11-18PublishedOnlineNovember2013inMECS()DOI:10.5815/ijcnis.2014.01.02Copyright©2014MECSI.J.ComputerNetworkandInformationSecurity,2014,1,11-18OnMaximaDistributionofFullDifferentialsandLinearHullsofBlockSymmetricCiphersLisitskiyK.E.NationalUniversityofRadioElectronics,Kharkiv,Ukrainedolgovvi@mail.ruAbstract—Theproblemofdeterminationofmaximadis-tributionlawsoffulldifferentialsandlinearbiasofblocksymmetricciphersassubstitutiontransformationsiscon-sidered.Well-knowntheoreticalresults,publishedinlit-erature,aregiven,aswellasexperimentresultsonmak-ingthelawsofmaximadistributionoffulldifferentialtransitionsandmaximumbiasessoflinearhullsforre-ducedciphermodelfromBelorussianstandardandcipherKalina,whichpracticallyconfirmtheoreticalcalculations,arepresented.Theresultstestifythatmaximumvaluesofdifferentialandlinearprobabilitiesareconcentratedclosetotheiraveragevaluesandforevaluationofindexesofcipherprovablesecurityit’senoughtomakeatestofproximityofdifferentialandlinearcipherindexes,re-ceivedforonearbitrarilytakencipherkeycorrespondingtoindexesofrandomsubstitutions.IndexTerms—Provablesecurity,ofindexevaluationofprovablesecurityinblocksymmetricciphers,distributionofmaximums,miniversionsciphersI.INTRODUCTIONThispaperdealswithanewmethodologyofindexevaluationofprovablesecurityinblocksymmetricci-phers[1],accordingtowhichthepropertiesofblocksymmetriccipherscanbeevaluatedonthebasisofstudy-ingpropertiesoftheirreducedmodels.Herewewanttoremindoneofthecentralthesesofthismethodologywhichisformulatedasastatement:Allmodernblockciphers1afteracertainnumberofcyclesindependentlyofthoseusedinS-blocksciphers(herewedon’tmeantheirdegenerateddesigns)acquirethepropertiesofrandomsubstitutions,i.e.accordingtotheircombinatorialindexes(thenumberofinversions,increasesandcycles)aswellasaccordingtothelawsoftransitiontabledistributionofXORdifferences(fulldif-ferentials)andthedistributionlawsofbiaslinearapprox-imationtables(linearhulls)theyrepeatthecorrespondingindexesofrandomsubstitutions.AsaresultthemaximavaluesoffulldifferentialsandlinearhullsmeaningscanbedeterminedbycalculationsfromtheformulasforthedistributionlawsoftransitionprobabilitiesforXORta-HerethecipherDESisnotconsideredasamodernonebecausethetransitiontotherandomsubstitutionisperformedforseparatecipherkeysin16cyclesbecauseofthepresentsof0-typecharacteristics.blesandbiastablesoflinearapproximationsofappropri-aterandomsubstitutions.Herewith,thetestofrandomindexesoflargecipherscanbeperformedonthebasisofthedevelopmentandfurtheranalysisofrandomindexesofreducedmodels,permittingtomakecalculatingexperimentsinacceptable(real)term.Thisresultistestedonagreatnumberofreducedandlargemodelsofmanymodernciphers[2-10andothers].Theexperimentsmadehoweveraretiedtothelimitedsetofencryptionkeys.Nevertheless,onthebasisoftheseresultstheconclusionwasmadethatciphersecurityin-dexescanbedeterminednotbytheaveragingmethodoverthesetofkeysbutonthebasisofmaximadetermi-nationofdifferentialandlinearprobabilitiesforany(one)arbitrarilytakencipherkey.WealsorecallthatusingthisapproachtheevaluationofblocksymmetricciphersecurityindexesisproposedtodonotwiththehelpMADP(MaximumAverageDiffer-entialProbability)andMALHP(MaximumAverageLin-earHullProbability),asitisdoneinagreatnumberofpublications,butwiththehelpofAMDP(AverageMax-imumDifferentialProbability)andAMLHP(AverageMaximumLinearHullProbability)which,asshowninpaper[11]aremoresuitabletotheproblemsolved.Inthispaperwewanttosubstantiatethevalidityoftheconclusion,alreadypresentedinanumberofworks[2-10]thattheblocksymmetriccipherssecurityagainstdiffer-entialandlinearattacksreallycanbedeterminednotbytheaveragingmethodoverasetofkeysbutonthebasisofmaximumdeterminationofdifferentialandlinearprobabilitiesforany(one)arbitrarilytakencipherkeypermittingtooconvincethatmaximumvaluesoffulldif-ferentialsandcipherlinearhullscoincidewiththecorre-spondingindexesofrandomsubstitutions.Thegeneralapproachtosolvingthisproblemistostudythebehaviorofciphertransformationonthewholesetofcipherkeys.Experimentallythisapproachisbasedontheevaluationwiththehelpofcomputingexperimentsthemaximumvaluesoffulldifferentialsandlinearhullbiassforreducedciphermodelsforthewholesetofci-pherkeys(thereducedciphermodelspermittodoit)andthedeterminationofmaximumexperimentallyobtainedvaluesandtheirnumberforthewholesetofdifferentialandsubstitutionlineartableastheciphersthemselvesareconsidered.Mathematically,thisproblemcaststothemaximumdistributionstudyonagreatnumberofindependent12OnMaximaDistributionofFullDifferentialsandLinearHullsofBlockSymmetricCiphersCopyright©2014MECSI.J.ComputerNetworkandInformationSecurity,2014,1,11-18randomvalues.ThispaperposestheproblemofdeterminationofthegreatestpossiblevaluesoftransitionsamongagreatnumberoftableXORdifferencesandbiasesstablesoflinearapproximationsofsmallciphermodelsforthewholesetofencryptionkeys.Thefirstpartofthepapergivestheoreticalfoundations,whicharethebasisofdeterminationofthemaximadis-tributionlawsofagreatnumberofrand

1 / 8
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功