|
Mathematical Methods of Cryptography
Search for differences for Alzette S-Box with maximum or close to maximum differential characteristic probability
A. A. Dmukh, D. O. Pasko Academy of Cryptography of the Russian Federation, Moscow, Russia
Abstract:
In this paper, we describe a “differential meet-in-the-middle” method for obtaining differences for 64-bit ARX permutation Alzette with maximum or close to maximum differential characteristic probability (DCP). The method is based on testing the high-probability differences in the middle rounds of Alzette and extending them to the previous and following rounds. Using this method, we obtain 7 differences for 4-rounds Alzette with DCP 2−6, 1 difference for 5-rounds Alzette with DCP 2−10, and 1 difference for 6-rounds Alzette with DCP 2−18. Same differences for 4 and 5 rounds were obtained by the developers of Alzette as the differences with maximum DCP, but our method has lower complexity: taking the calculation of probability for a round difference as a single operation, it's 36 operations (4 rounds), 135 operations (5 rounds) and 486 operations (6 rounds) for our method and more than 1.29⋅108 operations (4 rounds), 2⋅1.29⋅108 operations (5 rounds) and 1.03⋅1014 operations (6 rounds) for Alzette developers’ method. Also, we obtain 6 differences for 7-rounds Alzette with DCP 2−27 and 11 differences for 8-rounds Alzette with DCP 2−35 with complexity ⩽5⋅1013 operations for both cases. For these number of rounds by the developers of Alzette were obtained only the higher bounds for maximum DCP: 2−24 (7 rounds) and 2−32 (8 rounds). Our estimations of Alzette developers’ method complexity is ⩾2.97⋅1016 operations for 7-rounds Alzette and ⩾2.97⋅1016+4.75⋅1012 operations for 8-rounds Alzette.
Keywords:
permutation, Alzette, differential characteristic, differential method.
Citation:
A. A. Dmukh, D. O. Pasko, “Search for differences for Alzette S-Box with maximum or close to maximum differential characteristic probability”, Prikl. Diskr. Mat., 2022, no. 58, 40–56
Linking options:
https://www.mathnet.ru/eng/pdm784 https://www.mathnet.ru/eng/pdm/y2022/i4/p40
|
Statistics & downloads: |
Abstract page: | 119 | Full-text PDF : | 57 | References: | 26 |
|