SMS4 is a 128-bit block cipher used in the WAPI standard. WAPI is the Chinese national standard for securing Wireless LANs.
Since the specification of SMS4 was not released until January 2006, there have been only a few papers analyzing this cipher.
In this paper, firstly we present a kind of 5-round iterative differential characteristic of SMS4 whose probability is about
2− 42. Then based on this kind of iterative differential characteristic, we present a rectangle attack on 16-round SMS4 and a differential
attack on 21-round SMS4. As far as we know, these are the best cryptanalytic results on SMS4.
Keywords SMS4 - Block cipher - Differential characteristic - Rectangle attack - Differential cryptanalysis