reducing63aaa.com
63aaa.com 时间:2021-04-08 阅读:(
)
SCIENCECHINAInformationSciencesMarch2020,Vol.
63139111:1–139111:3https://doi.
org/10.
1007/s11432-018-9495-xcScienceChinaPressandSpringer-VerlagGmbHGermany,partofSpringerNature2020info.
scichina.
comlink.
springer.
com.
LETTER.
ImproveddistinguishersearchtechniquesbasedonparitysetsXiaofengXIE&TianTIAN*NationalDigitalSwitchingSystemEngineering&TechnologicalResearchCenter,P.
O.
Box407,Zhengzhou450001,ChinaReceived12February2018/Accepted15June2018/Publishedonline10February2020CitationXieXF,TianT.
Improveddistinguishersearchtechniquesbasedonparitysets.
SciChinaInfSci,2020,63(3):139111,https://doi.
org/10.
1007/s11432-018-9495-xDeareditor,DivisionpropertywasatechniqueproposedbyTodoatEUROCRYPT2015tosearchintegraldis-tinguishersagainstblockciphers[1].
Todo[2]ap-pliedthistechniquetoperformstructuralevalu-ationagainstboththeFeistelandtheSPNcon-structionsandattackedthefullMISTY1.
Sub-sequently,manyimprovedtechniquesbasedonthedivisionpropertywereproposed[3,4].
AtFSE2016,TodoandMorii[3]introducedthebit-baseddivisionpropertyandproveditseective-nesstonddistinguishersagainstnon-S-box-basedciphers.
Althoughmoreaccurateintegraldistinguisherswerefoundbyusingthebit-baseddivisionprop-erty,itcouldnotbeappliedtocipherswhoseblocklengthismorethan32becauseofitshightimeandmemorycomplexities.
BasedonTodo'swork,Xiangetal.
[5]convertedthedistinguishersearchalgorithmbasedonthebit-baseddivisionpropertyintoanMILPproblematASIACRYPT2016.
Withthismethod,theyobtainedaseriesofimprovedresultsincludinga9-roundPRESENTdistinguisherwithonebalancedbit.
Thisdistin-guisherisoneofthebest-knowndistinguishersre-latedtoroundnumbers.
AtCRYPTO2016,BouraandCauteaut[6]introducedtheparitysettostudythedivi-sionproperty.
TheyutilizedtheparitysettoexploitfurtherpropertiesofthePRESENTS-boxandthePRESENTlinearlayer,leadingtoseveralimproveddistinguishersagainstreduced-roundPRESENT.
BecausemorepropertiesoftheS-boxandthelinearlayerareutilized,paritysetscanndmoreaccurateintegralcharacteris-tics.
However,althoughtheauthorsdidnotpointout,aparitysetrequireshighertimeandmemorycomplexitiesthanthedivisionpropertydoes.
Ourworkaimsatreducingtimeandmemorycomplex-itieswhenusingparitysetstosearchintegraldis-tinguishers.
Asaresult,weintroducetheideaofmeet-in-the-middleintothedistinguishersearch.
Toillustrateourtechniques,weperformedexten-siveexperimentsonPRESENTandfounda9-rounddistinguisherwith22balancedbits.
Notation1(Bitproductfunction).
Letu,x∈Fn2.
Denotexu=ni=1x[i]u[i],andforu,x∈Fn12*Fn22Fnm2,wherex=(x1,x2,xm),u=(u1,u2,um),denebitproductfunctionasxu=mi=1xuii.
Notation2(Comparisonbetweenvectors).
Fora,b∈Zm,denoteabifaibiforall0bifabbuta=b.
Foru∈Fn2,letusdenotePrec(u)={v∈Fn2:vu},Succ(u)={v∈Fn2:uv}.
*Correspondingauthor(email:tiantiand@126.
com)XieXF,etal.
SciChinaInfSciMarch2020Vol.
63139111:2Theorem1.
Ifu,v∈Fnt2satisfyuv,thenW(u)W(v).
Notation3(Comparisonbetweensets).
LetAandBbetwosetswhoseelementsareinFn2.
De-noteABifthereexista∈Aandb∈Bwithab,andABifnoneofsuchcoupleexists.
Proposition1.
LetAandBbetwosetswhoseelementsareinFn2withAB.
Iftherearea1,a2∈A,b1,b2∈Bsuchthata2a1andb1b2,thenA\{a1}B\{b1}.
Notation4(Roundfunction).
LetFbeaper-mutationofFn2denedbyF:x=(x1,x2,xn)→y=(y1,y2,yn).
TheneveryyicanbeseenasaBooleanfunctiononx1,x2,xn,denotedbyyi=Fi(x).
Forapositiveintegerr,wedenoteFrasacompositionofrpermutationF.
Denition1(Divisionproperty[1]).
LetXbeamultisetwhoseelementsbelongtoFn2.
Then,XhasthedivisionpropertyDnkwhenitfulllsthefollowingconditions:Foru∈Fn2,theparityofxuoverallelementsinXisalwaysevenwhenwt(u)Forfurtherstudyofthedivisionprop-erty,pleasereferto[1,4]indetail.
Denition2(Parityset[6]).
LetXbeasetwhoseelementstakevaluesofFn2.
TheparitysetofXisdenotedbyU(X)anddenedasfollows:U(X)=u∈Fn2:x∈Xxu=1.
Remark1.
IftheparitysetU(X)ofXisknown,thenthedivisionpropertyofXisgivenbyDnk,wherek=minu∈U(X)wt(u).
ForthepropagationrulesoftheparitysetonSPN,pleasereferto[1].
ForaninputsetXandaroundfunctionE,de-notetheparitysetafterr1-roundencryptionasU(Er1(X)),andthealgebraicnormalform(ANF)ofthei-thoutputbitafterr2-roundencryptionasEr2i(x).
IfallthetermsappearinginEr2i(x)arenotdivisiblebyanytermin{xu:u∈U(Er(X))},thenthei-thoutputbitof(r1+r2)-roundencryp-tionisbalanced.
Basedonthisobservation,weimprovedthein-tegraldistinguishersearchbyutilizingthemeet-in-the-middletechniquewhichdividesthen-roundpropagationofparitysetsinton1-roundpropaga-tionofparitysetsand(nn1)-roundpropagationoftheANF.
Next,weproposeanewconcept,whichwecalltermset,todescribetheANFandshowtheprop-agationrulesofthetermsetonSPN.
Denition3(Termset).
Letf(x)beann-variableBooleanfunction.
Thetermsetoff(x)denotedbyT(f)isthesubsetofFn2denedbyT(f)={u∈Fn2:xuappearsintheANFoff(x)}.
Proposition2.
LetSbeanS-boxoverFm2.
De-noteTs(u)={v∈Fm2:xvappearsintheANFofSu(x)}.
Thenforanm-variableBooleanfunctionfwiththetermsetT(f),wehaveT(f(S(x)))u∈T(f)Ts(u).
Proposition3.
LetSbeapermutationofFmt2whichconsistsoftparallelindepen-dentS-boxesoverFm2,namely,S(x1,xt)=(S(x1)S(xt)).
Foranmt-variableBooleanfunctionfwiththetermsetT(f),wehaveT(f(S))(u1,···,ut)∈T(f)Ts1(u1)Tst(ut).
Proposition4.
Letfbeann-variableBooleanfunctionwiththetermsetT(f).
Foranyk∈Fn2,thetermsetoff(kx)=(x1k1,xnkn)satisesT(f(kx))u∈T(f)Prec(u).
Then,thetermsetafteroneroundencryptioncanbededucedbyPropositions2and4,i.
e.
,T(f(S(xk)))u∈T(f)v∈Ts(u)Prec(v),fork∈Fn2.
Theproofsofthesepropositionscouldbefoundthroughhttps://eprint.
iacr.
org/2018/447.
Wecanalsosearchdistinguishersbytermsetsonly.
Ifthereexistsau∈Fn2satisfyingSucc(u)T(Eri)=,thenar-rounddistinguisherwhoseinputsetisPrec(u)isfound.
However,thetimeandmemorycomplexitieswillbeveryhigh.
Thus,wetookadvantageofthemeet-in-the-middletechniquesothatthetermsetandtheparitysetcouldbecombinedtoreducetimeandmemorycomplexities.
Inordertondadistinguisher,weneedtocom-pareT(Er2i)withU(Er1(X))andverifywhetherT(Er2i)U(Er1(X)).
Ourdistinguishersearchalgorithmconsistsofvesteps,whichcanbede-scribedasfollows.
XieXF,etal.
SciChinaInfSciMarch2020Vol.
63139111:3Step1.
Choosethepropagationroundnum-bersr1andr2fortheparitysetandthetermsetrespectively,wherer1+r2=r.
Step2.
ChooseaninputsetX.
Step3.
CalculatetheparitysetU(Er1(X)).
Step4.
CalculatethetermsetsT(Er2i)for1in.
Step5.
CompareU(Er1(X))withT(Er2i)for1in.
IfU(Er1(X))T(Er2i),thenthei-thoutputbitinr-roundencryptionisbalanced.
Ifnoneofsuchintersectionsisempty,thenchooseanotherXandgotoStep2.
Wealsoproposesomenoveltechniquestomakeouralgorithmmoreecient.
Sizereduceoperation.
ForthetermsetT(Eri(x)),thesizereduceoperationRtremovesalltheelementsv∈T(Eri(x))suchthatthereisanelementv′∈T(Eri(x))withv′v.
Asforaparityset,theoperationRuremovesalltheelementsu∈U(Er1(X))suchthatthereisanelementu′∈U(Er1(X))withuu′.
ItcanbededucedfromProposition1thatthecom-parisonresultofT(Eri(x))andU(Er1(X))isthesameasthecomparisonresultofRt(T(Eri(x)))andRu(U(Er1(X))).
Observation1.
ThePRESENTsuperS-boxescanworkindependentlyinthe2-roundencryption.
Reducinglook-uptable.
BasedonObserva-tion1,wecaneasilyconstructa2-roundpropaga-tiontableforthesuperS-boxbycalculatingRuU(S(P(S(X))))forallpossibleinputs,whereSisapermutationofF4n2consistingoffourPRESENTS-boxesS(x1,x2,x3,x4)=(S(x1),S(x2),S(x3),S(x4)).
Multiplecomparison.
Thistechniqueat-temptstoremovethetermsthathavenomultipleinU;ifnotermisdivisiblebyavectorinU,thenitisclearthattheoutputbitisbalanced.
Wetriedtojudgesuchdivisibilityintermsofdegreeorderandalphabetorder.
Forthedetailsofthistech-nique,refertohttps://eprint.
iacr.
org/2018/447.
Toillustrateourtechniques,weapplyouralgo-rithmtothePRESENTdistinguishersearch.
Observation2.
ThecubictermsintheANFsofthesecondandfourthcoordinatesofthePRESENTS-box(sayS2andS4)arethesame[7].
Asaresult,thexorofthesetwocoordinatesS2S4=1x1x2x3x2x4x3x4hasonlydegree2.
Moreover,everyterminS2S4hasamultipleinS2andS4respectively.
Hence,S2S4maybebalancedevenifS2andS4areunbalanced.
Wetriedtond10-roundPRESENTdistin-guishersrst,buttheresultoftherightmostout-putbitisunbalancedforalltheinputsetswithdimension63.
ItseemsthattheANFofthisout-putbitisthesimplestamong64outputbits,andtherefore,ourresultsshowthatthePRESENTprobablyhasno10-roundintegraldistinguishersbyonlyusingthedivisionproperty.
Then,wefo-cusonthe9-roundPRESENT,andndadistin-guisherwith22balancedoutputbits.
Input:(aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaac),Output:b3b3bb2b2bb1b1bbbbbbbbbbbbbbbbb),where"c"meansaconstantbit,"a"meansanac-tivebit,""meansanunknownbit,and"b"meansabalancedbit.
Inaddition,thepresenceofbitswiththesamenotationbimeanstheiradditionisbalanced.
Conclusion.
Inthisstudy,weproposedacon-ceptcalledthetermsettopropagateinformationoftheANF.
Withtermsets,weimprovedthedis-tinguishersearchmethodbasedontheparitysetintermsofbothmemoryandtimecomplexities.
Fromtherelationbetweentheparitysetandthebit-baseddivisionproperty,itwasfoundthatthetermsetcouldalsobeappliedtoimprovethedis-tinguishersearchmethodbasedonthebit-baseddivisionproperty.
AcknowledgementsThisworkwassupportedbyNa-tionalNaturalScienceFoundationofChina(GrantNo.
61672533).
References1TodoY.
Structuralevaluationbygeneralizedintegralproperty.
LectNotesComputSci,2015,9056:287–3142TodoY.
IntegralcryptanalysisonfullMISTY1.
JCryptol,2017,30:920–9593TodoY,MoriiM.
Bit-baseddivisionpropertyandap-plicationtosimonfamily.
LectNotesComputSci,2016,9783:357–3774SunL,WangW,WangMQ.
Automaticsearchofbit-baseddivisionpropertyforARXciphersandword-baseddivisionproperty.
LectNotesComputSci,2017,10624:128–1575XiangZJ,ZhangWT,BaoZZ,etal.
ApplyingMILPmethodtosearchingintegraldistinguishersbasedondivisionpropertyfor6lightweightblockciphers.
LectNotesComputSci,2016,10031:648–6786BouraC,CanteautA.
Anotherviewofthedivisionproperty.
LectNotesComputSci,2016,9814:654–6827BogdanovA,KnudsenLR,LeanderG,etal.
PRESENT:anultra-lightweightblockcipher.
LectNotesComputSci,2007,4727:450–466
OneTechCloud发布了本月促销信息,全场VPS主机月付9折,季付8折,优惠后香港VPS月付25.2元起,美国CN2 GIA线路高防VPS月付31.5元起。这是一家2019年成立的国人主机商,提供VPS主机和独立服务器租用,产品数据中心包括美国洛杉矶和中国香港,Cera的机器,VPS基于KVM架构,采用SSD硬盘,其中美国洛杉矶回程CN2 GIA,可选高防。下面列出部分套餐配置信息。美国CN...
digital-vm在日本东京机房当前提供1Gbps带宽、2Gbps带宽、10Gbps带宽接入的独立服务器,每个月自带10T免费流量,一个独立IPv4。支持额外购买流量:20T-$30/月、50T-$150/月、100T-$270美元/月;也支持额外购买IPv4,/29-$5/月、/28-$13/月。独立从下单开始一般24小时内可以上架。官方网站:https://digital-vm.com/de...
A400互联怎么样?A400互联是一家成立于2020年的商家,A400互联是云服务器网(yuntue.com)首次发布的云主机商家。本次A400互联给大家带来的是,全新上线的香港节点,cmi+cn2线路,全场香港产品7折优惠,优惠码0711,A400互联,只为给你提供更快,更稳,更实惠的套餐,香港节点上线cn2+cmi线路云服务器,37.8元/季/1H/1G/10M/300G,云上日子,你我共享。...
63aaa.com为你推荐
小度商城小度怎么下载app?蓝色骨头手机宠物的一个蓝色骨头代表多少级,灰色又代表多少级,另外假如有骨头又代表多少级firetrap我淘宝店还是卖二单就被删,怎么回事!月神谭适合12岁男孩的网名,要非主流的,帮吗找找,谢啦qq530.com求教:如何下载http://www.qq530.com/ 上的音乐www.78222.com我看一个网站.www.snw58.com里面好有意思呀,不知道里面的信息是不是真实的www.zjs.com.cn中通快递投诉网站网址是什么?蜘蛛机器人在《红色警戒2共和国之辉》中,对付“蜘蛛机器人”的最好武器是什么?4399宠物连连看2.54399游戏里的宠物连连看3.1版本,电脑网页有,为什么手机里没有呢?我想下这个版本在手机上,因为酒仙琐事酒仙指的是谁?
vps租用 万网域名管理 cn域名个人注册 vir arvixe omnis gomezpeer sub-process 2017年黑色星期五 域名接入 域名和空间 linux服务器维护 网通服务器托管 电信托管 drupal安装 河南移动梦网 万网空间 国外网页代理 godaddy空间 网络速度 更多