Exact Maximum Expected Differential and Linear Probability for 2-Round Advanced Encryption Standard (AES)

نویسندگان

  • Liam Keliher
  • Jiayuan Sui
چکیده

Provable security of a block cipher against differential / linear cryptanalysis is based on the maximum expected differential / linear probability (MEDP / MELP) over T ≥ 2 core rounds. Over the past few years, several results have provided increasingly tight upper and lower bounds in the case T = 2 for the Advanced Encryption Standard (AES). We show that the exact value of the 2-round MEDP / MELP for the AES is equal to the best known lower bound: 53/2 ≈ 1.656 × 2−29 / 109, 953, 193/2 ≈ 1.638 × 2−28. This immediately yields an improved upper bound on the AES MEDP / MELP for T ≥ 4, namely (53/234)4 ≈ 1.881× 2−114 / (109, 953, 193/254)4 ≈ 1.802× 2−110.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Exact maximum expected differential and linear probability for two-round Advanced Encryption Standard

The current standard approach to demonstrate provable security of a block cipher against differential and linear cryptanalysis is based on the maximum expected differential and linear probability (MEDP and MELP) over a sequence of core cipher rounds. Often information about these values for a small number of rounds leads to significant insights concerning the security of the cipher for larger n...

متن کامل

A Novel Method for Impossible Differential Cryptanalysis of 9-round Aes-256

Through in-depth study of the 4-round encryption characteristics of advanced encryption standard (AES), a new 4-round differential path with a probability of existence at 2 -30 has been derived. Based on this path, a novel method was proposed for impossible differential cryptanalysis of 8-round AES-256. The analysis method requires 2 95 pairs of chosen plaintexts, approximately 2 163 units of m...

متن کامل

Refined Analysis of Bounds Related to Linear and Differential Cryptanalysis for the AES

The best upper bounds on the maximum expected linear probability (MELP) and the maximum expected differential probability (MEDP) for the AES, due to Park et al. [23], are 1.075 × 2−106 and 1.144 × 2−111, respectively, for T ≥ 4 rounds. These values are simply the 4 powers of the best upper bounds on the MELP and MEDP for T = 2 [3, 23]. In our analysis we first derive nontrivial lower bounds on ...

متن کامل

Novel Impossible Differential Cryptanalysis of Zorro Block Cipher

Impossible difference attack is a powerful tool for evaluating the security of block ciphers based on finding a differential characteristic with the probability of exactly zero. The linear layer diffusion rate of a cipher plays a fundamental role in the security of the algorithm against the impossible difference attack. In this paper, we show an efficient method, which is independent of the qua...

متن کامل

Differential Fault Analysis of the Advanced Encryption Standard using a Single Fault

In this paper we present an enhanced Differential Fault Attack that can be applied to the AES using a single fault. We demonstrate that when a single random byte fault is induced that affects the input of the eighth round, the AES key can be deduced using a two stage algorithm. The first step, would be expected to reduce the possible key hypotheses to 2, and the second step to a mere 2. Further...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2005  شماره 

صفحات  -

تاریخ انتشار 2005