Mixture Integral Attacks on Reduced-Round AES with a Known/Secret S-Box

Lorenzo Grassi, Markus Schofnegger*

*Korrespondierende/r Autor/-in für diese Arbeit

Publikation: Beitrag in Buch/Bericht/KonferenzbandBeitrag in einem KonferenzbandBegutachtung

Abstract

In this work, we present new low-data secret-key distinguishers and key-recovery attacks on reduced-round AES. The starting point of our work is “Mixture Differential Cryptanalysis” recently introduced at FSE/ToSC 2019, a way to turn the “multiple-of-8” 5-round AES secret-key distinguisher presented at Eurocrypt 2017 into a simpler and more convenient one (though, on a smaller number of rounds). By reconsidering this result on a smaller number of rounds, we present as our main contribution a new secret-key distinguisher on 3-round AES with the smallest data complexity in the literature (that does not require adaptive chosen plaintexts/ciphertexts), namely approximately half of the data necessary to set up a 3-round truncated differential distinguisher (which is currently the distinguisher in the literature with the lowest data complexity). For a success probability of 95%, our distinguisher requires just 10 chosen plaintexts versus 20 chosen plaintexts necessary to set up the truncated differential attack. Besides that, we present new competitive low-data key-recovery attacks on 3- and 4-round AES, both in the case in which the S-box is known and in the case in which it is secret.

Originalspracheenglisch
TitelProgress in Cryptology – INDOCRYPT 2020
Untertitel21st International Conference on Cryptology in India, Bangalore, India, December 13–16, 2020, Proceedings
Redakteure/-innenKarthikeyan Bhargavan, Elisabeth Oswald, Manoj Prabhakaran
ErscheinungsortCham
Herausgeber (Verlag)Springer
Seiten312-331|
Seitenumfang20
ISBN (Print) 978-3-030-65276-0
DOIs
PublikationsstatusVeröffentlicht - 2020
Veranstaltung21st International Conference on Cryptology in India - Virtuell, Indien
Dauer: 13 Dez. 202016 Dez. 2020

Publikationsreihe

NameLecture Notes in Computer Science
Band12578

Konferenz

Konferenz21st International Conference on Cryptology in India
KurztitelIndocrypt 2020
Land/GebietIndien
OrtVirtuell
Zeitraum13/12/2016/12/20

ASJC Scopus subject areas

  • Theoretische Informatik
  • Informatik (insg.)

Dieses zitieren