结构密码分析*??

来源 :密码学报 | 被引量 : 0次 | 上传用户:cqy2002
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
衡量密码算法安全性的重要指标是该算法抵抗已知攻击的能力。所谓结构密码分析指的是与密码算法非线性组件无关的密码分析方法,比如不可能差分分析、零相关线性分析以及计算活跃S盒数目的下界等。本文以SPN结构为例,介绍结构密码分析的基本原理和方法。文章首先提出了结构的概念,并研究了结构的差分传播规律,文章指出,若α_1→β_1和α_2→β_2均是SPN结构的可能差分,则α_1|α_2→β_1|β_2也是该SPN结构的可能差分;其次将这些规律用于分组密码针对不可能差分分析的可证明安全中,针对SPN结构线性扩散层P,提出了本原指数的概念,并利用线性扩散层P的本原指数刻画了SPN结构最长不可能差分的轮数,指出了在不考虑S盒细节的情况下,AES算法不可能差分最长轮数恰好为4,因此,若想利用不可能差分密码分析方法对AES算法取得突破,我们必须充分研究AES算法S盒的性质;文章进一步提出了对偶结构的概念,证明了密码结构的不可能差分与对偶结构的零相关线性掩码是等价的,从而可同时给出分组密码针对零相关线性分析的可证明安全。 An important indicator of cryptographic algorithm security is the ability of the algorithm to resist known attacks. The so-called structural cryptanalysis refers to the cryptanalysis method that has nothing to do with the non-linear components of the cryptographic algorithm, such as impossibility of differential analysis, zero-correlation linear analysis and calculation of the lower bound of the number of active S-boxes. This text takes SPN structure as an example, introduced the basic principle and method of structural password analysis. Firstly, the concept of structure is proposed and the law of differential propagation of structure is studied. The paper points out that if α_1 → β_1 and α_2 → β_2 are possible differences of SPN structure, then α_1 | α_2 → β_1 | β_2 is also possible for the SPN structure Secondly, we apply these rules to the demonstrable safety that the group cipher can not be differentially analyzed, and propose the concept of the primitive index for the linear diffusion layer P of SPN structure. The original index of the linear diffusion layer P is used to characterize the SPN It is pointed out that it is impossible for the AES algorithm to differentiate the longest number of rounds exactly without considering the details of the S-box. Therefore, if it is impossible to use the differential cryptanalysis to obtain the AES algorithm We must fully study the properties of the S-box of AES algorithm. We further propose the concept of dual structure, and prove that the impossibility difference of cryptographic structure is equivalent to the zero-correlation linear mask of dual structure, Proven security of passwords against zero-correlation linear analysis.
其他文献
近来河南省公布一项规定,即宾馆(酒店)、商场、写字楼等大型建筑物及居民住宅区,禁止使用国家领导人名字、外国人名和外国地名命名,这引发了公众热议.rn立法禁用洋地名无可厚
The Last Interglacial Period strata in the Milanggouwan section in the Salawusu River valley on the Ordos Plateau, China, have 8.5 sedimentary cycles composed a
由于铁电薄膜具有工作电压低、读写速度快及较好的耐久性等优点,在非易失存储器(FRAM)方面受到人们的广泛重视。在过去的十年里,研究的重点集中在Pb(Zr,Ti)O3(PZT)系铁电薄膜
3月21日-24日,2012年中国国际客车大赛专家评审会、五城市公交车辆招标入围评审会暨中国(南京)绿色公交技术创新应用论坛会在南京召开,会议由中国城市公共交通协会科学技术分会及
为了维护LonWorks技术在应用层的互操作性,在1 994年5月,由36家公司发起,成立了国际LonMark互操作协会(LonMark Interoperability Association),旨在指导各生产厂商的产品开
信息化建设促进了档案工作的创新,朝着协调、绿色、开放、共享的方向发展.2000年12月中共中央办公厅明确提出大力加强档案信息化建设的任务,至今历时18年,其间经历了电子公文
期刊
Gas concentrations and isotopic compositions of He and CO2 were determined on free gas samples from ten hot springs of the Rehai geothermal field, Tengchong, Ch
近年来,人工制备量子点、量子线等纳米结构材料引起了广泛关注。通常的制备方法有电子束刻蚀、离子束刻蚀、X射线刻蚀、电子全息成像刻蚀等。这类方法所能达到的最低尺度为≥