{"title":"SP分组密码截短差分的观察及其在mCrypton和CRYPTON V1.0中的应用","authors":"D. Yang, Wen-feng Qi, Huajin Chen","doi":"10.1049/iet-ifs.2017.0196","DOIUrl":null,"url":null,"abstract":"Truncated differential attack (TDA) proposed by Knudsen in Fast Software Encryption 1995 (FSE'95) has been widely used in the analysis of block ciphers. In this study, the authors specifically study the security of SP block ciphers against TDA. In FSE'15, Li et al.\n introduced a meet-in-the-middle technique to construct truncated differential for Feistel ciphers. They first apply Li's technique to SP block ciphers and get some further results. Second, they introduce the concept of generalised truncated difference to control the diffusion of active S-boxes in the truncated differential. On the basis of these, two 5-round truncated differential distinguishers for mCrypton and CRYPTON V1.0 have been constructed. Using these two 5-round distinguishers, they present the first 8-round DA on mCrypton-64 and improve the former best TDA on CRYPTON V1.0 by one round.","PeriodicalId":13305,"journal":{"name":"IET Inf. Secur.","volume":"50 1","pages":"419-424"},"PeriodicalIF":0.0000,"publicationDate":"2018-04-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Observations on the truncated differential of SP block ciphers and their applications to mCrypton and CRYPTON V1.0\",\"authors\":\"D. Yang, Wen-feng Qi, Huajin Chen\",\"doi\":\"10.1049/iet-ifs.2017.0196\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Truncated differential attack (TDA) proposed by Knudsen in Fast Software Encryption 1995 (FSE'95) has been widely used in the analysis of block ciphers. In this study, the authors specifically study the security of SP block ciphers against TDA. In FSE'15, Li et al.\\n introduced a meet-in-the-middle technique to construct truncated differential for Feistel ciphers. They first apply Li's technique to SP block ciphers and get some further results. Second, they introduce the concept of generalised truncated difference to control the diffusion of active S-boxes in the truncated differential. On the basis of these, two 5-round truncated differential distinguishers for mCrypton and CRYPTON V1.0 have been constructed. Using these two 5-round distinguishers, they present the first 8-round DA on mCrypton-64 and improve the former best TDA on CRYPTON V1.0 by one round.\",\"PeriodicalId\":13305,\"journal\":{\"name\":\"IET Inf. Secur.\",\"volume\":\"50 1\",\"pages\":\"419-424\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-04-04\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IET Inf. Secur.\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1049/iet-ifs.2017.0196\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Inf. Secur.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1049/iet-ifs.2017.0196","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Observations on the truncated differential of SP block ciphers and their applications to mCrypton and CRYPTON V1.0
Truncated differential attack (TDA) proposed by Knudsen in Fast Software Encryption 1995 (FSE'95) has been widely used in the analysis of block ciphers. In this study, the authors specifically study the security of SP block ciphers against TDA. In FSE'15, Li et al.
introduced a meet-in-the-middle technique to construct truncated differential for Feistel ciphers. They first apply Li's technique to SP block ciphers and get some further results. Second, they introduce the concept of generalised truncated difference to control the diffusion of active S-boxes in the truncated differential. On the basis of these, two 5-round truncated differential distinguishers for mCrypton and CRYPTON V1.0 have been constructed. Using these two 5-round distinguishers, they present the first 8-round DA on mCrypton-64 and improve the former best TDA on CRYPTON V1.0 by one round.