Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
|
 |
Security of Camellia against Truncated Differential Cryptanalysis
| |
|
Security of Camellia against Truncated Differential Cryptanalysis
Masayuki Kanda5, 6 and Tsutomu Matsumoto6 
| (5) |
NTT Information Sharing Platform Laboratories, 1-1 Hikari-no-oka, Yokosuka-shi, Kanagawa 239-0847, Japan |
| (6) |
Yokohama National University, 79-5 Tokiwadai, Hodogaya-ku, Yokohama-shi, Kanagawa 240-8501, Japan |
Abstract
This paper studies security against truncated differential cryptanalysis from the “designer’s” standpoint. In estimating the
security, we use the upper bound of truncated differential probability. Previous works, Knudsen, Matsui and Moriai et al.,
searched for effective truncated differentials to attack byte-oriented block ciphers and computed the exact probability of
the differentials. In this paper, we discuss the following items from the designer’s standpoint; (a) truncated differential
probability of effective active-s-box, (b) XOR cancellation probability, and (c) effect of auxiliary functions, e.g., FL/FL
-1-functions. We then combine them with Matsui’s search algorithm and evaluate the security of Camellia, jointly developed by
NTT and Mitsubishi Electric Corporation, against truncated differential cryptanalysis. We prove (from the designer’s standpoint)
that variants of Camellia with more than 11 rounds are secure against truncated differential cryptanalysis even if weak-key
FL/FL
-1-functions are taken into consideration.
Fulltext Preview (Small, Large)
 References secured to subscribers.
|
|
|
|
|
|