Key-Dependent Approximations in Cryptanalysis. An Application of Multiple Z4 and Non-Linear Approximations

Standaert, François-Xavier;Rouvroy, Gaël;Piret, G.;Quisquater, Jean-Jacques;Legat, Jean-Didier
(2003) 24th Symposium on Information Theory in the Benelux — Location: Veldhoven, The Netherlands (22.May.2003)

Files

10.pdf
  • Open Access
  • Adobe PDF
  • 207.6 KB

Details

Authors
Abstract
Linear cryptanalysis is a powerful cryptanalytic technique that makes use of a linear approximation over some rounds of a cipher, combined with one (or two) round(s) of key guess. This key guess is usually performed by a partial decryption over every possible key. In this paper, we investigate a particular class of non-linear boolean functions that allows to mount key-dependent approximations of s-boxes. Replacing the classical key guess by these key-dependent approximations allows to quickly distinguish a set of keys including the correct one. By combining different relations, we can make up a system of equations whose solution is the correct key. The resulting attack allows larger flexibility and improves the success rate in some contexts. We apply it to the block cipher Q. In parallel, we propose a chosen-plaintext attack against Q that reduces the required number of plaintext-ciphertext pairs from 2^97 to 2^87.
Affiliations

Citations

Standaert, F.-X., Rouvroy, G., Piret, G., Quisquater, J.-J., & Legat, J.-D. (2003). Key-Dependent Approximations in Cryptanalysis. An Application of Multiple Z4 and Non-Linear Approximations. 24th Symposium on Information Theory in the Benelux, Veldhoven, The Netherlands. https://hdl.handle.net/2078.5/253385