论文部分内容阅读
This paper presents a method for differential collision attack of reduced FOX block cipher based on 4-round distinguishing property. It can be used to attack 5, 6 and 7-round FOX64 and 5-round FOX128. Our attack has a precomputation phase, but it can be obtained before attack and computed once for all. This attack on the reduced to 4-round FOX64 requires only 7 chosen plaintexts, and performs 2~42.8 4-round FOX64 encryptions. It could be extended to 5 (6, 7)-round FOX64 by a key exhaustive search behind the fourth round. The time complexities of 5, 6 and 7-round FOX64 are approximate to 2~106.8, 2~170.8 and 2~234.8, respectively. The attack on reduced FOX128 demands 11 chosen plaintexts, requires 2~192 one round encryptions in precomputation, performs approximately 2~76.5 one round encryptions on 4-round FOX128, and is 2~204.5 against 5-round FOX128.
This paper presents a method for differential collision attack of reduced FOX block cipher based on 4-round distinguishing property. It can be used to attack 5, 6 and 7-round FOX64 and 5-round FOX128. Our attack has a precomputation phase, but This attack on the reduced to 4-round FOX64 requires only 7 chosen plaintexts, and performs 2 ~ 42.8 4-round FOX64 encryptions. It could be extended to 5 (6, 7) The time complexities of 5, 6 and 7-round FOX64 are approximate to 2 ~ 106.8, 2 ~ 170.8 and 2 ~ 234.8, respectively. The attack on reduced FOX128 demands 11 chosen Plaintexts, requiring 2 to 192 one round encryptions in precomputation, are approximately 2 to 76.5 one round encryptions on 4-round FOX 128, and 2 to 204.5 against 5-round FOX128.