Tongxin xuebao (Apr 2023)

Improved integral attack——random linear distinguish and key recovery attack

  • Shaoyu DU

Journal volume & issue
Vol. 44
pp. 145 – 153

Abstract

Read online

Based on the integral attack and collision attack of four rounds of AES, a random linear distinguish attack against four rounds of SP block ciphers was proposed, which took advantage of the non-uniformity of linear biases’ distribution between some blocks of plaintext and inner state.Combined with precomputation, a key recovery attack against four rounds of AES-like block ciphers was proposed.For LED-64, the results of distinguish attack and key recovery attack were given.Therein for LED-64 of 1-Step, the probability of successful distinguish attack is 85% under the condition that the data complexity is 28 and the computational complexity is 216 basic operation.For LED-64 of 2-Step, the calculation complexity of the key recovery attack under the condition of related key is 214 basic operation, the data complexity is 28, and the precomputation storage complexity is 238 half bytes.

Keywords