(2016) IET Information Security — Vol. 10, n° 2, p. 95-103 (2016)
Files
No attached file found for this publication.
Details
Authors
Liu, ZhiqiangShanghai Jiao Tong University
Author
Gu, DawuShanghai Jiao Tong University
Author
Sun, BingNational University of Defense Technology
Author
Wang, QingjuShanghai Jiao Tong University
Author
Varici, KeremUCLouvain
Author
Abstract
Camellia is one of the widely used block ciphers, which has been included in the NESSIE block cipher portfolio and selected as a standard by ISO/IEC. In this study, the authors observe that there exist some interesting properties of the FL/FL?1 functions in Camellia. With this observation they derive some weak keys for the cipher, based on which they present the first known 8-round zero-correlation linear distinguisher of Camellia with FL/FL?1 layers. This result shows that the FL/FL?1 layers inserted in Camellia cannot resist zero-correlation linear cryptanalysis effectively for some weak keys since the currently best zero-correlation linear distinguisher for Camellia without FL/FL?1 layers also covers eight rounds. Moreover, by using the novel distinguisher, they launch key recovery attacks on 13-round Camellia-192 and 14- round Camellia-256. To their knowledge, these results are the best for Camellia-192 and Camellia-256 with FL/FL?1 and whitening layers.
Liu, Z., Gu, D., Sun, B., Wang, Q., & Varici, K. (2016). Improved zero-correlation linear cryptanalysis of reduced-round Camellia under weak keys. IET Information Security, 10(2), 95-103. https://doi.org/10.1049/iet-ifs.2014.0614 (Original work published 2016)