TY - JOUR
T1 - The higher-order meet-in-The-middle attack and its application to the Camellia block cipher
AU - Lu, Jiqiang
AU - Wei, Yongzhuang
AU - Kim, Jongsung
AU - Pasalic, Enes
PY - 2014/3/27
Y1 - 2014/3/27
N2 - The Camellia block cipher has a 128-bit block length, a user key of 128, 192 or 256 bits long, and a total of 18 rounds for a 128-bit key and 24 rounds for a 192 or 256-bit key. It is a Japanese CRYPTREC-recommended e-government cipher, a European NESSIE selected cipher and an ISO international standard. The meet-in-The-middle attack is a technique for analysing the security of a block cipher. In this paper, we propose an extension of the meet-in-The-middle attack, which we call the higher-order meet-in-The-middle (HO-MitM) attack; the core idea of the HO-MitM attack is to use multiple plaintexts to cancel some key-dependent component(s) or parameter(s) when constructing a basic unit of "value-in-The-middle". Then we introduce a novel approach, which combines integral cryptanalysis with the meet-in-The-middle attack, to construct HO-MitM attacks on 10-round Camellia with the FL/FL-1 functions under 128 key bits, 11-round Camellia with the FL/FL-1 functions under 192 key bits and 12-round Camellia with the FL/FL-1 functions under 256 key bits. Finally, we apply an existing approach to construct HO-MitM attacks on 14-round Camellia without the FL/FL-1 functions under 192 key bits and 16-round Camellia without the FL/FL-1 functions under 256 key bits. The HO-MitM attack can potentially be used to cryptanalyse other block ciphers.
AB - The Camellia block cipher has a 128-bit block length, a user key of 128, 192 or 256 bits long, and a total of 18 rounds for a 128-bit key and 24 rounds for a 192 or 256-bit key. It is a Japanese CRYPTREC-recommended e-government cipher, a European NESSIE selected cipher and an ISO international standard. The meet-in-The-middle attack is a technique for analysing the security of a block cipher. In this paper, we propose an extension of the meet-in-The-middle attack, which we call the higher-order meet-in-The-middle (HO-MitM) attack; the core idea of the HO-MitM attack is to use multiple plaintexts to cancel some key-dependent component(s) or parameter(s) when constructing a basic unit of "value-in-The-middle". Then we introduce a novel approach, which combines integral cryptanalysis with the meet-in-The-middle attack, to construct HO-MitM attacks on 10-round Camellia with the FL/FL-1 functions under 128 key bits, 11-round Camellia with the FL/FL-1 functions under 192 key bits and 12-round Camellia with the FL/FL-1 functions under 256 key bits. Finally, we apply an existing approach to construct HO-MitM attacks on 14-round Camellia without the FL/FL-1 functions under 192 key bits and 16-round Camellia without the FL/FL-1 functions under 256 key bits. The HO-MitM attack can potentially be used to cryptanalyse other block ciphers.
KW - Block cipher
KW - Camellia
KW - Cryptology
KW - Integral cryptanalysis
KW - Meet-in-The-middle attack
UR - https://www.scopus.com/pages/publications/84895930057
U2 - 10.1016/j.tcs.2014.01.031
DO - 10.1016/j.tcs.2014.01.031
M3 - 文章
AN - SCOPUS:84895930057
SN - 0304-3975
VL - 527
SP - 102
EP - 122
JO - Theoretical Computer Science
JF - Theoretical Computer Science
ER -