  • 王沙沙,张文涛,向泽军.RECTANGLE-80的相关密钥差分分析[J].信息安全学报,2019,4(4):94-108    [点击复制]
  • WANG Shasha,ZHANG Wentao,XIANG Zejun.The Related-Key Differential Cryptanalysis of RECTANGLE-80[J].Journal of Cyber Security,2019,4(4):94-108   [点击复制]
【打印本页】 【下载PDF全文】 查看/发表评论下载PDF阅读器关闭


过刊浏览    高级检索

本文已被:浏览 6220次   下载 6070 本文二维码信息
王沙沙1,2, 张文涛1,2, 向泽军1,2
(1.中国科学院信息工程研究所信息安全国家重点实验室 北京 中国 100093;2.中国科学院大学网络空间安全学院 北京 中国 100049)
关键词:  轻量级分组密码  RECTANGLE  相关密钥差分分析  自动化搜索  差分特征
The Related-Key Differential Cryptanalysis of RECTANGLE-80
WANG Shasha1,2, ZHANG Wentao1,2, XIANG Zejun1,2
(1.State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;2.School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China)
RECTANGLE is a 25-round SP-network with a 64-bit block length and a 80-bit or 128-bit seed key. It uses bit-slice technique to have good performance on both hardware and software platforms. Based on Matsui and Moriai et al's approaches and two strategies proposed by Zhenzhen Bao et al., we investigate the security of RECTANGLE against related-key differential cryptanalysis by restricting the Hamming weights of the key difference at the narrowest point to the following 5 ranges:[1,1],[1,2],[1,3],[1,4], or[1,5]. Our purpose is to obtain the best reduced-round related-key differential characteristics in RECTANGLE. As a result, we obtain the best related-key differential characteristics of the first eight rounds in the five cases, the best related-key differential characteristics of nine rounds in the first two cases, and an upper bound on probabilities of the best related-key differential characteristic of nine rounds in the last three cases. Our results show that the probabilities of the best characteristics on the first eight rounds are the same in the last three cases. Hence, with the expansion of the range on Hamming weights, the probability of the best characteristics tend to be stable. When the Hamming weights belong to[1,1] or[1,2], the probability of the best 9-round characteristic is 2-42. When Hamming weights belong to[1,3],[1,4] or[1,5], the probability of the best 9-round characteristic is 2-41, 2-37, 2-34 respectively. We predict that the upper bound on probability of the best 9-round related-key differential characteristic is 2-41. Therefore, the upper bound on probability of the best 18-round related-key differential characteristic is 2-82, which shows that RECTANGLE-80 have enough security against related-key differential cryptanalysis.
Key words:  lightweight block cipher  RECTANGLE  related-key differential cryptanalysis  automatic search  differential characteristic