Division Property: Efficient Method to Estimate Upper Bound of Algebraic Degree
نویسنده
چکیده
We proposed the division property, which is a new method to find integral characteristics, at EUROCRYPT 2015. In this paper, we expound the division property, its effectiveness, and follow-up results. Higher-Order Differential and Integral Cryptanalyses. After the proposal of the differential cryptanalysis [1], many extended cryptanalyses have been proposed. The higher-order differential cryptanalysis is one of such extensions. The concept was first introduced by Lai [6] and the advantage over the classical differential cryptanalysis was studied by Knudsen [4]. Assuming the algebraic degree of the target block cipher Ek is upper-bounded by d for any k, the dth order differential is always constant. Then, we can distinguish the target cipher Ek as ideal block ciphers because it is unlikely that ideal block ciphers have such property, and we call this property the higher-order differential characteristics in this paper. The similar technique to the higher-order differential cryptanalysis was used as the dedicated attack against the block cipher Square [3], and the dedicated attack was later referred to the square attack. In 2002, Knudsen and Wagner formalized the square attack as the integral cryptanalysis [5]. In the integral cryptanalysis, attackers first prepare N chosen plaintexts. If the XOR of all corresponding ciphertexts is 0, we say that the cipher has an integral characteristic with N chosen plaintexts. The integral characteristic is found by evaluating the propagation of four integral properties: A, C, B, and U . Division Property. Before the introduction of the division property, it is important to understand the difference between the higher-order differential and integral cryptanalyses. Actually, we can regard both cryptanalyses as the same cryptanalysis. Nevertheless, the higher-order differential and integral characteristics are constructed by completely different methods, and either of both methods has its own advantages and disadvantages. Moreover, there are some experimental characteristics that cannot be proven by either of both methods. These observation causes significant motivation that we develop the division property. At Eurocrypt 2015, we proposed the division property, which is a novel technique to find integral (higher-order differential) characteristics [8]. This technique is the generalization of the integral property that can also exploit the algebraic degree at the same time. As a result, the division property can find integral characteristics that cannot be found by the two conventional methods. Let X be a subset whose elements take n-bit values, and assume that the set fulfills the division property D k . Then, ⊕ x∈X πu(x) is 0 and unknown when w(u) < k and w(u) ≥ k, respectively, where w(u) denotes the Hamming weight of u ∈ F2 . The division properties D n, D 2 , and D 1 correspond to the integral properties A, B, and U , respectively. Clearly, the division properties from D 3 to D n−1 are not used in the integral property. Moreover, let us consider the set S(X) whose elements are computed by applying the S-box S for elements in X. Then, if the algebraic degree of the S-box is at most d, the propagation of the division property is D k → D dk/de. The proposal paper of the division property at EUROCRYPT2015 only shows the usefulness of generic attacks against Feistel and Substitution-Permutation networks. To insist the usefulness of the division property, we applied the new technique to the cryptanalysis on full MISTY1 at CRYPTO2015 [7]. Then, many follow-up results have been reported [11, 9, 2, 10], and nowadays, new ciphers that discuss the security for the analysis using the division property in advance have been proposed.
منابع مشابه
ALGEBRAIC NONLINEARITY IN VOLTERRA-HAMMERSTEIN EQUATIONS
Here a posteriori error estimate for the numerical solution of nonlinear Voltena- Hammerstein equations is given. We present an error upper bound for nonlinear Voltena-Hammastein integral equations, in which the form of nonlinearity is algebraic and develop a posteriori error estimate for the recently proposed method of Brunner for these problems (the implicitly linear collocation method)...
متن کاملConvergence of Legendre wavelet collocation method for solving nonlinear Stratonovich Volterra integral equations
In this paper, we apply Legendre wavelet collocation method to obtain the approximate solution of nonlinear Stratonovich Volterra integral equations. The main advantage of this method is that Legendre wavelet has orthogonality property and therefore coefficients of expansion are easily calculated. By using this method, the solution of nonlinear Stratonovich Volterra integral equation reduces to...
متن کاملAlgebraic Degree Estimation of Block Ciphers Using Randomized Algorithm; Upper-bound Integral Distinguisher
Integral attack is a powerful method to recover the secret key of block cipher by exploiting a characteristic that a set of outputs after several rounds encryption has ( integral distinguisher). Recently, Todo proposed a new algorithm to construct integral distinguisher with division property. However, the existence of integral distinguisher which holds in additional rounds can not be denied by...
متن کاملHypo-efficient domination and hypo-unique domination
For a graph $G$ let $gamma (G)$ be its domination number. We define a graph G to be (i) a hypo-efficient domination graph (or a hypo-$mathcal{ED}$ graph) if $G$ has no efficient dominating set (EDS) but every graph formed by removing a single vertex from $G$ has at least one EDS, and (ii) a hypo-unique domination graph (a hypo-$mathcal{UD}$ graph) if $G$ has at least two minimum dominating sets...
متن کاملSharp Upper bounds for Multiplicative Version of Degree Distance and Multiplicative Version of Gutman Index of Some Products of Graphs
In $1994,$ degree distance of a graph was introduced by Dobrynin, Kochetova and Gutman. And Gutman proposed the Gutman index of a graph in $1994.$ In this paper, we introduce the concepts of multiplicative version of degree distance and the multiplicative version of Gutman index of a graph. We find the sharp upper bound for the multiplicative version of degree distance and multiplicative ver...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016