Block cipher impossible differential automatic security assessment method
By designing a differential automation security evaluation method for packet passwords based on the - traceable mode, the problem of insufficient application of existing methods and many variables is solved, and efficient automation of the security evaluation of lightweight packet passwords is achieved.
Patent Information
- Application Number
- CN202510262577.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-06
AI Technical Summary
The existing impossible differential automation search method is difficult to effectively evaluate the security of lightweight packet passwords in the problem that it is not widely used and has a large number of variables.
A method for automated security evaluation of packet cipher impossible differentials based on the - traceability mode is proposed. By designing a new impossible differential divider architecture, this architecture involves fewer variables and has stronger versatility.
Automation of packet password security evaluation is achieved, reducing the number of variables, extending the application prospects of the method, and improving the efficiency of evaluation.
Smart Images

Figure CN119996251A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to the field of information security, and in particular to an impossible differential automatic security assessment method for block ciphers. Background Art
[0002] In recent years, Internet of Things (IoT) devices have been deployed in many fields. Their operations usually involve access, storage, and communication of sensitive and critical information that needs to be protected. However, due to limited resources and the need for low production costs, lightweight cryptographic algorithms have emerged. At present, many lightweight block ciphers have been proposed internationally, such as Present, Simon and Speck, Piccolo, etc. In order to meet the demand for lightweight passwords, NIST launched a project to solicit, evaluate, and standardize lightweight cryptographic algorithms suitable for use in resource-constrained environments. The security research of lightweight block cipher algorithms has always been a hot issue in the field.
[0003] Impossible differential cryptanalysis was first proposed by Biham et al. and Knudsen, who analyzed the security of Skipjack and DEAL respectively. Subsequently, this analysis method was widely used in many block ciphers, such as CRYPTON, ARIA, Camellia, Piccolo-80, Piccolo-128, etc. After manually searching for impossible differential distinguishers, some automated methods for searching impossible differentials of block ciphers have emerged, such as -method (Kim J, Hong S, Sung J, et al. Impossible Differential Cryptanalysis for Block CipherStructures [M] / / Johansson T, Maitra S. Progress in Cryptology-INDOCRYPT 2003: Vol. 2904. Berlin, Heidelberg: Springer Berlin Heidelberg, 2003: 82-96.) and UID-method (Luo Y, Lai X, Wu Z, et al. Aunified method for finding impossible differentials of block cipher structures [J]. Information Sciences, 2014, 263: 211-220.), both of which are aimed at word-based block ciphers. But -method requires the target algorithm to have a special property: the differential characteristic matrix of encryption and decryption has the "1" property, that is, the number of "1" in each column of the matrix is 0 or 1. This property leads to its limited application in block ciphers. -The improvement of the method uses more contradictions to detect impossible differential discriminators. In addition, since the XOR relationship of the differential variables is preserved and propagated, the UID-method reduces -The block cipher structure in the method has the limitation of "1" property matrix. However, the number of variables will still increase significantly with the iteration of the round function, which is similar to -Same as in the method. Summary of the invention
[0004] The present invention is directed to -method and UID-method have problems of insufficient application and too many variables. This paper proposes an automated security assessment method for impossible differential block ciphers. The word-based block ciphers are used as the research object. Based on the traceable pattern and -method, design a variant of the traceability pattern, i.e. -Traceable model, and based on -Traceability mode proposes a new architecture for constructing impossible differential distinguishers, which involves fewer variables and has greater generality.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] A block cipher impossible differential automated security assessment method, comprising:
[0007] use - Traceability mode models the internal state of a block cipher;
[0008] Automatically search for the longest impossible differential distinguisher of block ciphers, and obtain the structure and number of the longest impossible differential distinguishers;
[0009] The security of the block cipher is evaluated based on the structure and number of the longest impossible differential distinguishers of the block cipher.
[0010] Furthermore, for the - Traceability mode. In terms of describing the differential state, the differential is divided into five traceability modes: zero differential, non-zero non-fixed differential, non-zero fixed differential, XOR sum of non-zero fixed differential and non-zero non-fixed differential, and non-fixed differential. The symbols corresponding to each traceability mode are as follows:
[0011]
[0012] Furthermore, the operation rules between the traceability modes include:
[0013]
[0014] Among them, the table on the left shows the output traceable patterns corresponding to the five traceable patterns after passing through the bijective nonlinear function F or S box, and the table on the right shows the XOR result of any two traceable patterns.
[0015] Furthermore, the two -The contradiction of the traceable model is defined as follows: for all five - Traceable mode, any two - A traceability pattern is contradictory if and only if there is no - Differentiation of traceable patterns.
[0016] Further, the automatic search for the longest impossible differential distinguisher of the block cipher comprises:
[0017] Step a1: Let r=1, num=0; r represents the number of impossible differential rounds, and num represents the number of impossible differentials;
[0018] Step a2: Input -Traceability mode X=(X n-1 ,...,X1,X0)∈{0,1} n and output - Traceability model Y = (Y n-1 ,...,Y1,Y0)∈{0,1} n , let the initial internal state of the encryption direction be - Traceability mode Decryption direction of the internal state of the rth round - Traceability mode Execute steps a3 to a6; wherein X i ,Y i ∈{0,1} represents the word - traceability mode, i = 0, 1, ..., n-1, n represents the number of words;
[0019] Step a3: For i from 1 to r, perform the following operations: Calculate the internal state of the i-th round in the encryption direction according to the round function and the mode operation rules of the encryption direction. - Traceability mode make Indicates that the number of rounds is r and the input difference is All possible differential trajectories of ;
[0020] Step a4: For i from r to 1, perform the following operations: Calculate the internal state of the rith round in the decryption direction according to the round function and the mode operation rule of the decryption direction - Traceability mode make Indicates that the number of rounds is r and the output difference is All possible differential trajectories of ;
[0021] Step a5: Judgment and Whether there is a contradiction between each round and each element, if so, an impossible differential distinguisher with round number r, input difference X, and output difference Y is obtained, and the value of counter num is increased by one;
[0022] Step a6: Determine whether num is 0. If it is 0, output r-1 and the algorithm ends. At this time, the value of r-1 is the longest impossible differential round number; otherwise, set r=r+1, num=0 and execute step a2.
[0023] Furthermore, the method can also automatically search for impossible differential distinguishers of the r rounds, including:
[0024] Step b1: set num=0;
[0025] Step b2: Input -Traceability mode X=(X n-1 ,...,X1,X0)∈{0,1} n and output - Traceability model Y = (Y n-1 ,...,Y1,Y0)∈{0,1} n , let the initial internal state of the encryption direction be - Traceability mode Decryption direction of the internal state of the rth round - Traceability mode Execute steps b3 to b5; wherein X i ,Y i ∈{0,1} represents the word - traceability mode, i = 0, 1, ..., n-1, n represents the number of words;
[0026] Step b3: For i from 1 to r, perform the following operations: Calculate according to the round function and the mode operation rules of the encryption direction make Indicates that the number of rounds is r and the input difference is All possible differential trajectories of ;
[0027] Step b4: For i from r to 1, perform the following operations: Calculate the internal state of the rith round in the decryption direction according to the round function and the mode operation rule of the decryption direction - Traceability mode make Indicates that the number of rounds is r and the output difference is All possible differential trajectories of ;
[0028] Step b5: Judgment and Whether there is a contradiction between each round and each element, if so, an impossible differential distinguisher with round number r, input difference X, and output difference Y is obtained, and the value of counter num is increased by one;
[0029] Step b6: Output num, where the value of num is the number of impossible differential distinguishers in round r.
[0030] Furthermore, in step b5, it can be selected whether to output X and Y as needed.
[0031] Compared with the prior art, the present invention has the following beneficial effects:
[0032] The present invention is directed to -method and UID-method have problems of insufficient application and too many variables. This paper proposes an automated security assessment method for impossible differential block ciphers. The word-based block ciphers are used as the research object. Based on the traceable pattern and -method, design a variant of the traceability pattern, i.e. -Traceable model, and based on -Traceable patterns construct a new architecture for impossible differential distinguishers, which is a general extension method with broad application prospects and involves fewer variables. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 A diagram showing a counterexample structure of a matrix with the property of "1" provided in an embodiment of the present invention;
[0034] Figure 2 A schematic diagram of a flow chart of a method for automated security assessment of impossible differentials of a block cipher according to an embodiment of the present invention;
[0035] Figure 3 The exemplary structure of Example 1 provided in the embodiment of the present invention - Schematic diagram of the propagation of traceability patterns;
[0036] Figure 4 A schematic diagram of an 11-round impossible differential of an exemplary structure provided for an embodiment of the present invention;
[0037] Figure 5 A schematic diagram of the Gen-Skipjack round function structure provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0038] For ease of understanding, some of the terms that appear in the specific embodiments of the present invention are explained as follows:
[0039] (1) -method
[0040] -method is a general method that can find various impossible differential features of block cipher structures with certain properties. This method is applicable to word-based block cipher algorithms with bijective S-boxes. It uses the differential properties of words to realize the automated search for impossible differential distinguishers. -method, there are five types of differences: zero difference, non-zero non-fixed difference, non-zero fixed difference, XOR of non-zero fixed difference and non-zero non-fixed difference, and non-fixed difference. -The symbols used in the method and the corresponding difference variable types are shown in Table 1.
[0041] Table 1 - Symbols of variables in methods
[0042] symbol Corresponding difference type 0 Zero differential 1 Non-zero non-fixed difference <![CDATA[1 * ]]> Non-zero fixed differential <![CDATA[2 * ]]> XOR of a non-zero fixed difference and a non-zero non-fixed difference t(t≥2) Non-fixed differential
[0043] Kim et al. transformed differential propagation in block ciphers into matrix operations and defined the operation rules of differential variables in matrix operations. -The method requires that the differential characteristic matrix of encryption and decryption has the "1" property, that is, the number of "1" in each column of the matrix is 0 or 1. A specific example is given below.
[0044] Example 1: With the help of Figure 1 The example structure shown illustrates the properties of the "1" property. Since there are multiple "1"s in the second and third columns of the matrix ε, the example structure does not have a "1" property matrix. In other words, we cannot use -Method searches for impossible differential discriminators of example structures.
[0045] In addition, for -method, the number of variables is v+4, where v is the number of non-fixed differences. As the round function is iterated, the number of non-fixed differences will increase, which will lead to a very large number of variables.
[0046] -The method is based on the middle phase error technique, and some contradictions will be used to generate impossible differential distinguishers. Note that the contradiction is based on specific input differentials and output differentials, rather than on five differential types. It is necessary to consider whether there is a contradiction between the values of the differentials corresponding to the two differential types. For example, 1 * and 2 * Whether a contradiction can be formed depends on whether the non-zero fixed differences in the input and output differences take the same value. Assume that γ and γ′ are two non-zero fixed differences with different values, and δ is a non-zero non-fixed difference. When the non-zero fixed differences in the input and output differences are both γ, γ⊕δ≠γ. In this case, 2* cannot correspond to 1*. Otherwise, the contradiction does not hold, because γ can be equal to γ′⊕δ.
[0047] (2) UID-method
[0048] In 2014, Luo et al. proposed the UID-method, which is a -The improvement of the method reduces some limitations of the original method and adds some new conditions for judging contradictions. The UID-method mainly studies word-based iterative block ciphers with bijective S-boxes and automates the search for impossible differential distinguishers through matrix operations. For the UID-method, the differentials are divided into four types: zero differential, non-zero non-fixed differential, non-zero fixed differential, and non-fixed differential. The symbols used in the UID-method are defined in Table 2.
[0049] Table 2 Symbols of variables in the UID-method
[0050] symbol express 0 Zero differential li Non-zero non-fixed difference mi Non-zero fixed differential ri Non-fixed differential
[0051] The contradiction between two difference vectors is defined as follows:
[0052] Definition 1: Two difference vectors X = (Xn-1, Xn-2, ..., X0) and Y = (Yn-1, Yn-2, ..., Y0) are contradictory if there exists a subset Make the XOR of the differences in the subsets always unequal, that is,
[0053]
[0054] For example, if X = (l1⊕m1,l1⊕m1⊕m2) and Y = (m3,m3), then X and Y are contradictory because X0⊕X1=m2 cannot equal Y0⊕Y1=0. However, these two vectors are -method. Therefore, the UID-method exploits more contradictions to detect impossible differential distinguishers. In addition, since the XOR relationship of the differential variables is preserved and propagated, the UID-method reduces -The block cipher structure in the method has the limitation of "1" property matrix. However, the number of variables will still increase significantly with the iteration of the round function, which is similar to -Same as in the method.
[0055] The present invention will be further explained below with reference to the accompanying drawings and specific embodiments:
[0056] like Figure 2 As shown, a block cipher impossible differential automated security assessment method comprises:
[0057] use - Traceability mode models the internal state of a block cipher;
[0058] Automatically search for the longest impossible differential distinguisher of block ciphers, and obtain the structure and number of the longest impossible differential distinguishers;
[0059] The security of the block cipher is evaluated based on the structure and number of the longest impossible differential distinguishers of the block cipher.
[0060] The technical solution of the present invention is described in detail below.
[0061] 1. An architecture that makes differentiation impossible
[0062] In this section, we introduce and discuss a new architecture for constructing impossible-differential discriminators, called We first use -Traceability mode models the internal state. Then, we introduce a -Automated search methods for traceable patterns and analyze their complexity. and -method and UID-method were compared.
[0063] 1.1 Use - Traceability patterns model internal states
[0064] In this section, we propose - Traceability mode.
[0065] Definition 2 (Traceability pattern): If each internal state of a block cipher can be divided into n basic units (a basic unit can be 1 bit or 1 word), each unit has some specific properties (such as differential properties or linear properties), and if these properties can always be passed from one round to another with probability 1, these specific properties are called traceability patterns, and the set of these properties is called a traceability pattern set.
[0066] -The traceability mode is an abstraction and improvement of the two methods mentioned above. Originated from -method. In describing the differential state, the differential can be divided into five traceable modes: zero differential, non-zero non-fixed differential, non-zero fixed differential, XOR sum of non-zero fixed differential and non-zero non-fixed differential, and non-fixed differential. In describing the propagation of differentials, we use the operation between traceable modes to characterize the propagation of differentials in block ciphers. This operation is faster than -method and UID-method matrix operations are simpler and less restrictive. - The symbols used in the traceability modes are defined in Table 3. The operation rules between the traceability modes are shown in Table 4.
[0067] Table 3 - Symbols for traceable patterns
[0068] symbol describe 0 Zero differential 1 Non-zero fixed differential 2 Non-zero non-fixed difference 3 XOR of non-zero fixed difference and non-zero non-fixed difference 4 Non-fixed differential
[0069] Table 4 Operation rules between traceability modes
[0070]
[0071] The left side of Table 4 shows the output traceability patterns of the five traceability patterns after passing through the bijective nonlinear function F or S box. The right side of Table 4 shows the XOR result of any two traceability patterns.
[0072] two -The contradictory definition of traceability mode is as follows.
[0073] Definition 3: For all five - Traceable mode, any two - A traceability pattern is a pattern contradiction if and only if there is no pattern that belongs to both - Differentiation of traceable patterns.
[0074] The "0-1" model and the "0-2" model are naturally contradictory. -When the differential propagation represented by the traceable pattern is analyzed, we found the following fact. If the 1 pattern in the input and output differentials has the same difference, the XOR sum of the two 1 patterns is the 0 pattern, and the XOR sum of the 1 pattern and the 3 pattern is the 2 pattern. For example, if α is a non-zero fixed difference and β is a non-zero non-fixed difference, which means that α⊕β is the 3 pattern, then α⊕α=0 is the zero difference, that is, the 0 pattern, and α⊕(α⊕β)=β is the 2 pattern. In this case, the 1 pattern represents the same non-zero fixed difference, which means that the XOR of the two active patterns can be an inactive pattern. This will reduce the speed of differential diffusion and make the differential fully diffused in longer rounds. For block ciphers, how to find the longest impossible difference and evaluate the security of the block cipher based on the impossible differential analysis is a very important issue that designers need to consider. Therefore, in this case, we give the operation rules between traceable patterns. Since the 1-mode and 3-mode also lead to contradictions, the contradictions used to detect impossible differentiation are the "0-1" mode contradiction, the "0-2" mode contradiction, and the "1-3" mode contradiction.
[0075] The above situation does exist in practice, because analysts only need to take the same difference for all active words in a specific analysis. In order to better explain the operation rules of the traceable mode, we will use the example structure in Example 2.
[0076] Example 2: Assume input - The traceable pattern is (0,0,1,1), where all 1 patterns have the same non-zero fixed difference, then the example structure -Traceable mode of transmission Figure 3 shown.
[0077] 1.2 Based on -Impossible differential automated search architecture for traceable patterns
[0078] In this section, we propose a - Impossible differential automated search architecture for traceable patterns, using To represent this architecture.
[0079] because - The traceability mode is word-based, and "0,1" represents zero differential and non-zero fixed differential respectively, so traversing non-zero X = (X n-1 ,...,X1,X0) and Y=(Y n-1 ,...,Y1,Y0),X i ,Y i ∈{0,1}, i=0,1,...,n-1, we can judge whether all differences are impossible differences, where X=(X n-1 ,...,X1,X0) represents the input - Traceability mode, Y=(Y n-1 ,...,Y1,Y0) represents the output -Traceability mode, X i ,Y i ∈{0,1} represents the word - traceable pattern, n represents the number of words. In general, it is not possible to construct a differential discriminator using the middle phase stagger technique, The contradiction in is the pattern contradiction that has been analyzed and discussed in the previous section. In addition, the construction of this discriminator is based on two directions: encryption direction and decryption direction.
[0080] We use R' (r) and R' (-r) express - The result of r-round propagation of the traceable mode in the encryption direction and the decryption direction. In order to detect whether the input difference X and the output difference Y are an impossible difference of r rounds, it is first necessary to "encrypt" X and "decrypt" Y according to the operation rules between the traceable modes. The internal state of the i-th round in both directions -The traceability modes are represented as and Then, check whether there is Contradictory If exists If it is a contradictory pattern, store X and Y.
[0081] Algorithm 1 uses Pseudocode for searching for the longest impossible difference discriminator.
[0082]
[0083]
[0084] Algorithm 2 can calculate the number of impossible differences of any length and choose whether to output the corresponding impossible difference structure as needed.
[0085]
[0086] Example 3: For the example structure, running Algorithm 1 can get the longest impossible difference is 11 rounds. -The impossible difference constructed by the traceable pattern is shown in Table 5. To verify its correctness, we will give an example to illustrate how to use pattern contradiction to judge the impossible difference. The details of the 11-round impossible difference (0,0,0,α)→(α,0,0,0) are shown in Figure 4 As shown in the figure, α is a non-zero fixed difference. The output difference of the i-th round in the encryption direction is expressed as Indicates; the output difference of the i-th round in the decryption direction is expressed as express.
[0087] Table 5 The longest impossible difference of the example structure obtained using Algorithm 1
[0088]
[0089] Since the input difference of 11 rounds of impossible difference is (0, 0, 0, α), where α is a non-zero fixed difference, the difference U after 3 rounds is 3 is (α,0,0,0).
[0090] The output difference of 11 rounds of impossible differences is (α, 0, 0, 0), where α is a non-zero fixed difference. According to the decryption process, the following analysis is made.
[0091] 1. Due to V 11 =(α,0,0,0), so V 10 =(0,α,α,0).
[0092] 2. Due to Therefore V 9 =(0,0,α,0).
[0093] 3. Due to V 9 =(0,0,α,0), so V 8 =(0,0,0,α).
[0094] 4. Since a non-zero fixed differential α will result in a non-zero non-fixed differential β after F8, V 7 =(α,β,0,0).
[0095] 5.V 6 =(0,α,α⊕β,β).
[0096] 6. Since a non-zero fixed difference β passing through F6 will result in a non-zero non-fixed difference γ, we have
[0097] 7.
[0098] because And γ is a non-zero non-fixed difference, so we have Therefore, the differential feature of 11 rounds (0,0,0,α)→(α,0,0,0) is an impossible differential in theory. In order to verify this impossible differential through experiments, we use the S-box in PRESENT (Bogdanov A, Knudsen LR, Leander G, et al. PRESENT: An Ultra-Lightweight Block Cipher [C] / / Paillier P, Verbauwhede I. Cryptographic Hardware and Embedded Systems-CHES 2007. Berlin, Heidelberg: Springer, 2007: 450-466.) as the F function in the example structure. Then, the example structure can be regarded as a block cipher with 4 branches, and the branch size is 4 bits. Traversing and searching the plaintext space, we found that there is no pair of plaintext and ciphertext that satisfies the differential of 11 rounds (0,0,0,α)→(α,0,0,0),α≠0,α∈{0,1} 4 Therefore, the difference output by Algorithm 1 is indeed an impossible difference. The experiment took a total of 10.5 seconds.
[0099] By running Algorithm 2, we can obtain impossible differences of some other round numbers of the example structure, as shown in Table 6.
[0100] Table 6 Impossible differentiation of example structures
[0101]
[0102] 1.3 Complexity Analysis
[0103] Usually, in order to determine whether a differential feature is an impossible differential, its corresponding input differential and output differential should be given. For a block cipher with a plaintext size of mn bits, the differential features with non-zero input and output differentials are (2 mn -1)(2 mn -1). However, since most block ciphers have mn ≥ 64, where mn represents the block size and m represents the word size, it is unrealistic to test all non-zero differential features. But for word-based differential analysis, the differential of each sub-block is either zero or non-zero, and there are only these two possibilities. Therefore, the time complexity can be reduced from (2 mn -1) 2 Reduce to (2 n -1) 2 For example, the parameters for AES are n=16, m=8, and the time complexity is reduced to (2 16 -1) 2 ≈2 32 .
[0104] For an iterative block cipher of n words, the data complexity of Algorithm 1 can be ignored. For an r-round cipher algorithm, it is necessary to retain the traceable pattern of each round and each word to detect whether there is a pattern contradiction. This storage space can be used repeatedly when detecting differential features. Therefore, the storage complexity can also be ignored. The time complexity of Algorithm 1 consists of two parts. The first part is the complexity of traversing all non-zero differential features. The second part is to determine whether there is a pattern contradiction for each word in each round, but this item can be ignored. Therefore, the time complexity is (2 n -1) 2 ≈O(2 2n ).
[0105] 1.4 and Comparison between -method and UID-method
[0106] -method: The "1" property and the number of nonlinear bijective functions in the round function limit the -method application. In , the differential propagation in the word-based iterative block cipher is transformed into a mode operation, which solves the above limitations. For example, the example structure in Example 1 does not have the "1" property, so -method cannot be analyzed for its security, but Can.
[0107] UID-Method: Fewer variables are used. For the UID-method, the difference is calculated by variables 0, l i ,m i ,r i , i∈{1,2,...}. Each sub-block in the internal state of the cipher requires a variable to store the differential information. The number of variables is determined by the number of blocks of the block cipher and the number of iterations of the round function. Therefore, if the UID-method is used to search for impossible differentials of a block cipher with a large number of blocks and iterations, the number of variables will be very large. This problem can be solved because it only uses five variables, "0,1,2,3,4", to trace the propagation of differences. Figure 5For the UID method, (Luo Y, Lai X, Wu Z, et al. A unified method for finding impossible differentials of block cipher structures [J]. Information Sciences, 2014, 263: 211-220.) found 16 rounds of impossible differentials (0, 0, 0, l1) → (l2, 0, 0, l2) containing 10 variables, but for Table 7 shows the 16 rounds of impossible differencing involving 5 variables. Table 8 shows More results are obtained. Under the same circumstances, our time complexity is much smaller than that of the UID-method. The time complexity of the UID-method is ((n+1) n -1) 2 ,and The time complexity of (2 n -1) 2 , where n is the number of words. For Gen-Skipjack, the UID-method uses 10 variables and the time complexity is ((4+1) 4 -1) 2 ≈2 18.57 However, our method uses only 5 variables and has a time complexity of (2 4 -1) 2 ≈2 7.81 , is the 2nd of UID-method -10.76 .
[0108] The most important difference between the three methods lies in the classification of differences. -method, the differences are divided into five types, and the compatibility between them can be used to construct impossible differences. In order to search more accurately, Luo et al. took into account more differential information. In the UID-method, the differences are divided into four types, but the variables of each type represent different differential values. It is worth noting that neither method uses non-fixed differences to construct contradictions, but they take up a lot of storage space. In addition, for large blocks and block ciphers with a large number of iterations, the number of variables grows exponentially. Therefore, in In the framework, differences are divided into five types, and each sub-block involved in the internal state of the cipher has only five possible assignments.
[0109] Table 7 is based on The resulting 16-round Gen-Skipjack cannot be differentiated
[0110]
[0111] Table 8 Impossible differentials of Gen-Skipjack
[0112]
[0113] 2 Applications
[0114] To verify the correctness of the architecture, we will Applied to ten typical block ciphers and structures. For one IoT cipher, we found a full-round ID and two IDs with five more rounds than the full round. For two ISO standard ciphers, we found an ID with one more round than the previous result and two new IDs with the same length as the previous longest ID. Table 9 summarizes the detailed results and comparisons.
[0115] Specifically, for ALLPC, we found 1756 full-round (25-round) IDs and two 30-round IDs. For SKINNY, we found 408 new IDs with 11 rounds considering single-key and monotonic handles. On further investigation, 12 IDs with one more round than previous results were also found. For CLEFIA, two new 9-round IDs with the same length as the previous longest ID were found using our framework. For LBlock, TWINE, Feistel, Gen-RC6, Gen-Skipjack, Gen-CAST256, and SMS4, we rediscovered known IDs.
[0116] Table 9 Summary of impossible differentials for ten block ciphers and structures
[0117]
[0118]
[0119] in:
[0120] Reference 1: Beierle C, Jean J, S,et al.The SKINNY Family of BlockCiphers and its Low-Latency Variant MANTIS[C] / / Advances in Cryptology-CRYPTO2016.2016.
[0121] Literature 2: Mala H, Dakhilalian M, Shakiba M. Impossible Differential Attacks on 13-Round CLEFIA-128[J]. Journal of Computer Science and Technology, 2011, 26(4): 744-750.
[0122] Literature 3: Luo Y, Lai X. Improvements for Finding Impossible Differentials of Block Cipher Structures[J]. Security and Communication Networks, 2017, 2017: 1-9.
[0123] Literature 4: Suzaki T, Minematsu K, Morioka S, et al. TWINE: A Lightweight Block Cipher for Multiple Platforms*[C] / / Selected Areas in Cryptography: 19th International Conference. 2012.
[0124] Literature 5: Kim J, Hong S, Sung J, et al. Impossible Differential Cryptanalysis for Block Cipher Structures[M] / / Johansson T, Maitra S. Progress in Cryptology - INDOCRYPT 2003: Vol. 2904. Berlin, Heidelberg: Springer Berlin Heidelberg, 2003: 82-96.
[0125] Literature 6: Luo Y, Lai X, Wu Z, et al. A unified method for finding impossible differentials of block cipher structures[J]. Information Sciences, 2014, 263: 211-220.
[0126] Document 7: Choy J, Yap H. Impossible Boomerang Attack for Block CipherStructures[M] / / Takagi T, Mambo M. Advances in Information and ComputerSecurity: Vol. 5824. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009: 22-37.
[0127] Document 8: Yap H.Impossible Differential Characteristics of ExtendedFeistel Networks with Provable Security against Differential Cryptanalysis[M] / / Kim H kon, Kim T hoon, Kiumi A. Advances in Security Technology: Vol. 29. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009: 103-121.
[0128] In summary, with the increasing development of the Internet of Things, the demand for lightweight block ciphers is increasing. In this paper, we propose a new architecture for constructing impossible differential distinguishers Applicable to word-based block ciphers or structures. First, we extend the traceability pattern to such ciphers and structures. Then, we transform the propagation of differences in the target object into operations of these five patterns. Finally, we propose an architecture for constructing impossible differential distinguishers by using pattern operations and the middle phase shift technique. The architecture does not require the round function of the target object to have the "1" property, which makes the architecture have a wider range of applications. The time complexity is O(2 2n), where n represents the number of words, and the complexity of data and storage can be ignored. As an application, we analyzed 10 lightweight block cipher algorithms and structures. For the block cipher ALLPC suitable for the Internet of Things, a full-round impossible differential and two impossible differential distinguishers with 5 more rounds than the full round were obtained. For the international ISO standard SKINNY, an impossible differential distinguisher with 1 more round than the previous optimal result was found; for the international ISO standard CLEFIA, 2 new impossible differential distinguishers with the same number of rounds as the current longest were found. For LBlock, TWINE, Feistel, Gen-RC6, Gen-Skipjack, Gen-CAST256 and SMS4, some known impossible differential distinguishers were rediscovered. A large number of practical applications have confirmed that It is an efficient and universal method.
[0129] The above is only a preferred embodiment of the present invention. It should be pointed out that a person skilled in the art can make several improvements and modifications without departing from the principle of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A method for automated security assessment of impossible differential block ciphers, characterized in that: include: use - Traceability mode models the internal state of a block cipher; Automatically search for the longest impossible differential distinguisher of block ciphers, and obtain the structure and number of the longest impossible differential distinguishers; The security of the block cipher is evaluated based on the structure and number of the longest impossible differential distinguishers of the block cipher.
2. The method for automatic security assessment of impossible differential block ciphers according to claim 1, characterized in that: For the - Traceability mode. In terms of describing the differential state, the differential is divided into five traceability modes: zero differential, non-zero non-fixed differential, non-zero fixed differential, XOR sum of non-zero fixed differential and non-zero non-fixed differential, and non-fixed differential. The symbols corresponding to each traceability mode are as follows: 。 3. The method for automated security assessment of impossible differential block ciphers according to claim 2, characterized in that: The operating rules between the traceability modes include: Among them, the table on the left shows the output traceable patterns corresponding to the five traceable patterns after passing through the bijective nonlinear function F or S box, and the table on the right shows the XOR result of any two traceable patterns.
4. The method for automatic security assessment of impossible differential block ciphers according to claim 2, characterized in that: two -The contradiction of the traceable model is defined as follows: for all five - Traceable mode, any two - A traceability pattern is contradictory if and only if there is no - Differentiation of traceable patterns.
5. The method for automatic security assessment of impossible differential block ciphers according to claim 3, characterized in that: The automated search for the longest impossible differential distinguisher of a block cipher comprises: Step a1: Let r=1, num=0; r represents the number of impossible differential rounds, and num represents the number of impossible differentials; Step a2: Input -Traceability mode X=(X n-1 ,...,X1,X0)∈{0,1} n and output -Traceability mode Y=(Y n-1 ,...,Y1,Y0)∈{0,1} n , let the initial internal state of the encryption direction be - Traceability mode Decryption direction of the internal state of the rth round - Traceability mode Execute steps a3 to a6; wherein X i ,Y i ∈{0,1} represents the word - traceability mode, i = 0, 1, ..., n-1, n represents the number of words; Step a3: For i from 1 to r, perform the following operations: Calculate the internal state of the i-th round in the encryption direction according to the round function and the mode operation rules of the encryption direction. - Traceability mode make Indicates that the number of rounds is r and the input difference is All possible differential trajectories of ; Step a4: For i from r to 1, perform the following operations: Calculate the internal state of the rith round in the decryption direction according to the round function and the mode operation rule of the decryption direction - Traceability mode make Indicates that the number of rounds is r and the output difference is All possible differential trajectories of ; Step a5: Judgment and Whether there is a contradiction between each round and each element, if so, an impossible differential distinguisher with round number r, input difference X, and output difference Y is obtained, and the value of counter num is increased by one; Step a6: Determine whether num is 0. If it is 0, output r-1 and the algorithm ends. At this time, the value of r-1 is the longest impossible differential round number; otherwise, set r=r+1, num=0 and execute step a2.
6. The method for automatic security assessment of impossible differential block ciphers according to claim 1, characterized in that: The method can also automate the search for impossible differential discriminators of r rounds, including: Step b1: set num=0; Step b2: Input -Traceability mode X=(X n-1 ,...,X1,X0)∈{0,1} n and output -Traceability mode Y=(Y n-1 ,...,Y1,Y0)∈{0,1} n , let the initial internal state of the encryption direction be - Traceability mode Decryption direction of the internal state of the rth round - Traceability mode Execute steps b3 to b5; wherein X i ,Y i ∈{0,1} represents the word - traceability mode, i = 0, 1, ..., n-1, n represents the number of words; Step b3: For i from 1 to r, perform the following operations: Calculate according to the round function and the mode operation rules of the encryption direction make Indicates that the number of rounds is r and the input difference is All possible differential trajectories of ; Step b4: For i from r to 1, perform the following operations: Calculate the internal state of the rith round in the decryption direction according to the round function and the mode operation rule of the decryption direction - Traceability mode make Indicates that the number of rounds is r and the output difference is All possible differential trajectories of ; Step b5: Judgment and Whether there is a contradiction between each round and each element, if so, an impossible differential distinguisher with round number r, input difference X, and output difference Y is obtained, and the value of counter num is increased by one; Step b6: Output num, where the value of num is the number of impossible differential distinguishers in round r.
7. The method for automatic security assessment of impossible differential block ciphers according to claim 6, characterized in that: In step b5, it can be selected whether to output X and Y as needed.
Citation Information
Patent Citations
Searching method for impossible differential path of related key of block cipher
CN106027226A
Method for rapidly improving SPN type block cipher differential path probability
CN116155475A
Automatic security assessment method and device for block cipher algorithm
CN117294418A
Impossible difference search device, impossible difference search method, and program
JP2011013633A
A system and method for encryption and decryption of text
WO2020008446A2