Improved zero-correlation linear cryptanalysis of reduced-round Camellia under weak keys

Liu, Zhiqiang;Gu, Dawu;Sun, Bing;Wang, Qingju;Varici, Kerem
(2016) IET Information Security — Vol. 10, n° 2, p. 95-103 (2016)

Files

No attached file found for this publication.

Details

Authors
  • Liu, ZhiqiangShanghai Jiao Tong University
    Author
  • Gu, DawuShanghai Jiao Tong University
    Author
  • Sun, BingNational University of Defense Technology
    Author
  • Wang, QingjuShanghai Jiao Tong University
    Author
  • Varici, KeremUCLouvain
    Author
Abstract
Camellia is one of the widely used block ciphers, which has been included in the NESSIE block cipher portfolio and selected as a standard by ISO/IEC. In this study, the authors observe that there exist some interesting properties of the FL/FL?1 functions in Camellia. With this observation they derive some weak keys for the cipher, based on which they present the first known 8-round zero-correlation linear distinguisher of Camellia with FL/FL?1 layers. This result shows that the FL/FL?1 layers inserted in Camellia cannot resist zero-correlation linear cryptanalysis effectively for some weak keys since the currently best zero-correlation linear distinguisher for Camellia without FL/FL?1 layers also covers eight rounds. Moreover, by using the novel distinguisher, they launch key recovery attacks on 13-round Camellia-192 and 14- round Camellia-256. To their knowledge, these results are the best for Camellia-192 and Camellia-256 with FL/FL?1 and whitening layers.
Affiliations

Citations

Liu, Z., Gu, D., Sun, B., Wang, Q., & Varici, K. (2016). Improved zero-correlation linear cryptanalysis of reduced-round Camellia under weak keys. IET Information Security, 10(2), 95-103. https://doi.org/10.1049/iet-ifs.2014.0614 (Original work published 2016)