Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

On MISTY1 Higher Order Differential Cryptanalysis

Steve BabbageContact Information and Laurent FrischContact Information

(5)  Vodafone Ltd, The Courtyard, 2-4 London Road, Newbury, RG14 1JX, ENGLAND
(6)  France Télécom Recherche & Développement,DTL/SSR, 38-40, avenue du General Leclerc, 92794 Issy les Moulineaux Cedex 9, FRANCE
Abstract
MISTY1 is a block cipher whose design relies on an assertion of provable security against linear and difierential cryptanalysis. Yet, a simplified and round reduced version of MISTY1 that does not alter the security provability can be attacked with higher order difierential cryptanalysis. We managed to explain this attack by deriving the attacking property from the choice of an atomic component of the algorithm, namely one of the two MISTY1 S-boxes. This allowed us to classify the good and the bad S-boxes built with the same principles and to show that none of the S-boxes with optimal linear and difierential properties has an optimal behaviour with respect to higher order difierential cryptanalysis.

Contact Information Steve Babbage
Email: steve.babbage@vf.vodafone.co.uk

Contact Information Laurent Frisch
Email: laurent.frisch@francetelecom.fr
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this chapter
Export this chapter as RIS | Text
 
Remote Address: 38.107.191.109 • Server: mpweb05
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)