The Joltik-BC,adopting the substitution-permutation network structure and Tweakey framework,was a lightweight tweakable block cipher published at ASIACRPYPT 2014.By researching the internal characteristic of the Joltik-BC,a 6-round meet-in-the-middle distinguisher against the Joltik-BC-128 was constructed by controlling the tweakey differentials and combining differential enumeration and differential characteristics of S-boxes.An im-proved meet-in-the-middle attack against the 9-round Joltik-BC-128 was developed using this distinguisher.The memory and time complexities of the improved 9-round Joltik-BC-128 were 244.91 64-bits blocks and 248 9-round Joltik-BC-128 encryptions.Compared with existing meet-in-the-middle attack results,the time complexity and memory complexity of this method were significantly reduced.
分析密码学选修课程的教学现状和内容设置,在总结近几年教学存在问题的基础上,从授课内容、授课方法、考核方式、教材选取、兴趣培养、实际应用等方面进行探讨,提出一些行之有效的教学策略.
Cryptographic identification is a critical aspect of cryptanalysis and a fundamental premise for key recovery.With the advancement of artificial intelligence, cryptanalysis based on machine learning has become increasingly mature, providing more effective methods and valuable insights for cryptographic identification.The distinguishability experiments were performed based on the Machine Learning to identify the structures of block ciphers in conditions of random keys.The identification of two structures of block ciphers from theoretical and experimental angles was studied.The differences of features in two structures’ cipher texts have been deduced by introducing the runs distribution index, feature distribution functions, KL-divergence, etc.After completing the feasibility research, experiments to identify the structures of two block ciphers using two Machine Learning models and the runs distribution index were conducted.The experiments were divided into two groups: single algorithm group and mixture algorithms group.It is found that the accuracy of both groups are more than 80%, which is around 40% higher than former work.The problem of identifying the structures of Block Ciphers in the conditions of random keys is solved in detail.Meanwhile, differences between the two structures of block ciphers are verified, which can serve as a reference for the design of cryptography algorithms.
In CRYPTO 2019, Gohr successfully applied deep learning to differential cryptanalysis against the NSA block cipher Speck32/64, achieving higher accuracy than traditional differential distinguishers. Until now, the improvement of neural differential distinguishers is a mainstream research direction in neural-aided cryptanalysis. But the current development of training data formats for neural distinguishers forms barriers: (1) The source of data features is limited to linear combinations of ciphertexts, which does not provide more learnable features to the training samples for improving the neural distinguishers. (2) Lacking breakthroughs in constructing data format for network training from the deep learning perspective. In this paper, considering both the domain knowledge about deep learning and information on differential cryptanalysis, we use the output features of the penultimate round to proposing a two-dimensional and non-realistic input data generation method of neural differential distinguishers. Then, we validate that the proposed new input data format has excellent features through experiments and theoretical analysis. Moreover, combining the idea of multiple ciphertext pairs, we generate two specific models for data input construction: MRMSP(Multiple Rounds Multiple Splicing Pairs) and MRMSD(Multiple Rounds Multiple Splicing Differences) and then build new neural distinguishers against Speck and Simon family, which effectively improve the performance compared with the previous works. To the best of our knowledge, our neural distinguishers achieve the longest rounds and the higher accuracy for NSA block ciphers Speck and Simon.
AbstractCRAFT is a lightweight block cipher designed by Beierle et al. to effectively resist differential fault attacks at fast software encryption 2019. In this article, Demirci‐Selçuk meet‐in‐the‐middle (DS‐MITM) attacks on round‐reduced CRAFT based on automatic search are proposed. A DS‐MITM automatic search model for CRAFT was constructed, and then, the automatic search model was used to detect a 9‐round DS‐MITM distinguisher. The strong relations between the round‐subtweakeys were observed and the key‐dependent sieve technique was adopted to reduce the memory complexity of the attack. Based on the 9‐round distinguisher, a 19‐round DS‐MITM attack can be presented. Due to the strong key relations, the time complexity can be reduced by the key‐bridging technique and the equivalent round‐subtweakey. The time complexity of the 19‐round DS‐MITM attack is 2114.68 19‐round CRAFT encryption, the data complexity is 256 chosen plaintexts, and the memory complexity is 2109 64‐bit blocks. Adding one round to the end of the 19‐round DS‐MITM attack, a 20‐round DS‐MITM attack can be proposed. The time complexity of the 20‐round attack is 2126.94 20‐round CRAFT encryption, the data complexity is 256 chosen plaintexts, and the memory complexity is 2109 64‐bit blocks.
Deoxys-BC is an internal tweakable block cipher of the authenticated encryption algorithm Deoxys, which is a third-round finalist in the CAESAR competition. In this paper, we study the property of Deoxys-BC, such as the subtweakey difference cancelation and the freedom of the tweak. Combining the differential enumeration technique with these properties, the authors achieve the key-recovery attacks on Deoxys-BC under the meet-in-the-middle attack. As a result, we get an attack on 9-round Deoxys-BC-128-128 by constructing a 6-round meet-in-the-middle distinguisher with $2^{113}$ plaintext–tweak combinations, $2^{97}$ Deoxys-BC blocks and $2^{121.6}$ 9-round Deoxys-BC-128-128 encryptions. We also present an attack on 11-round Deoxys-BC-256-128 for the first time by constructing a 7-round meet-in-the-middle distinguisher with $2^{113}$ plaintext-tweak combinations, $2^{226}$ Deoxys-BC blocks and $2^{251}$ 11-round Deoxys-BC-256-128 encryptions.
KATAN ciphers are block ciphers using non-linear feedback shift registers. In this study, the authors improve the results of conditional differential analysis on KATAN by using deep learning. Multi-differential neural distinguishers are built to improve the accuracy of the neural distinguishers and increase the number of its rounds. Moreover, a conditional differential analysis framework is proposed based on deep learning with the multi-differential neural distinguishers, resulting in a significant improvement than the previous. We present a practical key recovery attack on the 97-round KATAN32 with 2(15.5) data complexity and 2(20.5) time complexity. The attack of the 82-round KATAN48 and 70-round KATAN64 are also presented as the best known practical results.
针对KATAN48算法的安全性分析问题,提出了一种基于神经区分器的KATAN48算法条件差分分析方法.首先,研究了多输出差分神经区分器的基本原理,并将它应用于KATAN48算法,根据KATAN48算法的数据格式调整了深度残差神经网络的输入格式和超参数;其次,建立了KATAN48算法的混合整数线性规划(MILP)模型,并用该模型搜索了前加差分路径及相应的约束条件;最后,利用多输出差分神经区分器,至多给出了80轮KATAN48算法的实际密钥恢复攻击结果.实验结果表明,在单密钥下,KATAN48算法的实际攻击的轮数提高了10轮,可恢复的密钥比特数增加了22比特,数据复杂度和时间复杂度分别由234和234降至216.39和219.68.可见,相较于前人单密钥下的实际攻击,所提方法能够有效增加攻击轮数和可恢复的密钥比特数,同时降低攻击的计算复杂度.
At CRYPTO 2019, Ghor applied deep learning to the cryptanalysis of block ciphers and presented neural distinguishers instead of purely differential distinguishers, which improved key recovery attacks of Speck32/64 using Bayesian optimization. In this paper, the authors attempt to improve the performance of neural distinguishers (NDs) and apply new NDs to present practical key recovery attacks on KATAN ciphers. First, with the help of MILP model, we present a (related-key) conditional differential neural distinguishers ((RK)CDNDs) of KATAN ciphers. The (RK)CDNDs use a new data format, combining with conditions and multiple differences. Compared to previous work, we greatly improve the number of rounds and the accuracy of NDs in both single-key and related-key scenarios. Moreover, a related-key conditional differential cryptanalysis framework based on deep learning is proposed with the RKCDNDs, resulting in a significant improvement from the previous. We present a practical key recovery attack on the 125-round KATAN32. The data complexity is 2 15.7 and the time complexity is 2 19.9 . We also present 106-round KATAN48 and 95-round KATAN64 practical key recovery attacks. The extension of key recovery attack improves the results for two more rounds by calculating the wrong key response profile in parallel. Our work not only increases the number of attack rounds and the recoverable key bits, but also reduces the computational complexity.
Kiasu-BC algorithm is an internal tweakable block cipher of authenticated encryption algorithm Kiasu as one of first-round candidates in the CAESAR competition.The precomputation complexity is reduced by utilizing the freedom of the tweak and the internal key restriction through the research on structural characteristics of Kiasu-BC algorithm based on AES-128 round function.Combined with the differential enumeration technique, a new 5-round meet-in-the-middle distinguisher was constructed to improve the meet-in-the-middle attack on 8-round Kiasu-BC algorithm.The improved attack requires the time complexity of 2114, the memory complexity of 263 and the data complexity of 2108.
MIBS is a Feistel structured lightweight block cipher aimed at extremely constrained resources environment. In this paper, an 8-round meet-in-the-middle distinguisher of MIBS is constructed by utilizing multiset and effective differential enumeration technique. Then, the meet-in-the-middle attacks on 12-round and 13-round MIBS-80 are proposed based on the new distinguisher. In the attack process, the plaintexts are filtered utilizing the differential properties and the guessed keys are reduced using the relation of master key and round key in the key expansion algorithm of MIBS-80. The time complexity of attacking 12-round and 13-round MIBS-80 is 253.2 and 262, respectively. Compared with the known results of the meet-in-the-middle attack, the number of rounds of meet-in-the-middle attack on MIBS-80 is increased by 2-round.
Joltik ‐ BC is an internal tweakable block cipher of the authenticated encryption algorithm Joltik, which was a second ‐ round finalist in the CAESAR competition. The authors study the key ‐ recovery attacks on Joltik ‐ BC under meet ‐ in ‐ the ‐ middle attack. Utilising the subtweakey difference cancellation, the freedom of the tweak and the differential enumeration, they attack on nine ‐ round Joltik ‐ BC ‐ 64 ‐ 64 by constructing a precise six ‐ round meet ‐ in ‐ the ‐ middle distinguisher with 2 53 plaintext–tweak combinations, 2 52.91 Joltik ‐ BC blocks and 2 54.1 nine ‐ round Joltik ‐ BC ‐ 64 ‐ 64 encryptions. Moreover, they attempt to attack on 11 ‐ round Joltik ‐ BC ‐ 128 ‐ 64 for the first time by constructing a seven ‐ round meet ‐ in ‐ the ‐ middle distinguisher with 2 53 plaintext–tweak combinations, 2 114 Joltik ‐ BC blocks and 2 123 11 ‐ round Joltik ‐ BC ‐ 128 ‐ 64 encryptions.
A study on the structure of ARIA cipher is presented. A new 4-round distinguishing property for the meet-in-the-middle attack on ARIA cipher is presented by making use of the multiset and the truncated differential char-acteristic. The new distinguishing property improves the meet-in-the-middle attack on 7 rounds of ARIA-192 cipher ef-fectively by reducing the 30 parameters to 16. The new attack requires a precomputation complexity of 2135.3and a time complexity of about 2123.
3D cipher is a new block cipher with Substitution-Permutation Network(SPN) structure.Unlike the Advanced Encryption Standard(AES),3D cipher uses a 3-dimensional state.Based on the structure of 3D cipher and meet-in-the-middle attack on 10-round 3D cipher,a new meet-in-the-middle attack is given by introducing multiset.The attack requires a precomputation complexity of 2319 and a time complexity of about 2326.8.Compared with the previous published meet-in-the-middle cryptanalytic results,the attack reduces the precomputation complexity and time complexity.