Decorrelated Fast Cipher: An AES Candidate Well Suited for Low Cost Smart Card Applications

نویسندگان

  • Guillaume Poupard
  • Serge Vaudenay
چکیده

In response to the call for candidates issued by the National Institute for Standards and Technologies (the Advanced Encryp-tion Standard project) the Ecole Normale Sup erieure proposed a candidate called DFC as for \Decorrelated Fast Cipher", based on the decor-relation technique that provides provable security against several classes of attacks (in particular the basic version of Biham and Shamir's Differential Cryptanalysis as well as Matsui's Linear Cryptanalysis). From a practical point of view, this algorithm is naturally very eecient when it is implemented on 64-bit processors. In this paper, we describe the implementation we made of DFC on a very low cost smart card based on the Motorola 6805 processor. The performances we obtain prove that DFC is also well suited for low cost devices applications. Since the beginning of commercial use of symmetric encryption (with block ciphers) in the seventies, construction design used to be heuristic-based and security was empiric: a given block cipher was considered to be secure until some researcher published an attack on. The Data Encryption Standard 1] initiated an important open research area, and some important cryptanalysis methods emerged, namely Biham and Shamir's diierential cryptanalysis 4] and Matsui's linear cryptanalysis 11], as well as further generalizations. Nyberg and Knudsen 14] showed how to build toy block ciphers which provably resist diierential cryptanalysis (and linear crypt-analysis as well as has been shown afterward 3]). This paradigm has successfully been used by Matsui in the MISTY cipher 12, 13]. However Nyberg and Knud-sen's method does not provide much freedom for the design, and actually, this paradigm leads to algebraic constructions. This may open the way to other kind of weaknesses as shown by Jakobsen and Knudsen 8]. In response to the call for candidates for the Advanced Encryption Standard (AES) which has been issued by the National Institute of Standards and Technology (NIST) the ENS proposed in 6] the Decorrelated Fast Cipher (DFC) 1. It is a block cipher which is faster than DES and hopefully more secure than triple-DES. It accepts 128-bit message blocks and any key size from 0 to 256. We believe that it can be adapted to any other cryptographic primitive such as 1 See

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Decorrelated Fast Cipher: an Aes Candidate Well Suited for Low Cost Smart Cards Applications

In response to the call for candidates issued by the National Institute for Standards and Technologies (the Advanced Encryption Standard project) the Ecole Normale Sup erieure proposed a candidate called DFC as for \Decorrelated Fast Cipher", based on the decorrelation technique that provides provable security against several classes of attacks (in particular the basic version of Biham and Sham...

متن کامل

Secure and Efficient Crypto System Based On 128-Bit AES

The AES algorithm was selected in 2000 by the US National Institute of Standards and Technologies (NIST) as a replacement to the Data Encryption Standard (DES) cryptographic algorithm. It is based on Rijndael algorithm which is a symmetric-key algorithm that processes fixed data of 128-bit blocks. The AES algorithm is suited for an efficient implementation on a wide range of processors. It can ...

متن کامل

Decorrelated Fast Cipher : an AES

This report presents a response to the call for candidates issued by the National Institute for Standards and Technologies (the Advanced Encryption Standard project). The proposed candidate | called DFC as for \Decorrelated Fast Cipher" | is based on Vaudenay's decor-relation technique. This provides provable security against several classes of attacks which include the basic version of Biham a...

متن کامل

ASIC Implementations of the Block Cipher SEA for Constrained Applications

SEA is a scalable encryption algorithm targeted for small embedded applications. It was initially designed for software implementations in controllers, smart cards or processors. In this paper, we investigate its hardware performances in a 0.13 μm CMOS technology. For these purposes, different designs are detailed. First, a single clock cycle per round loop architecture is implemented. Beyond i...

متن کامل

New Results on the Two sh Encryption Algorithm

Two sh is a 128-bit block cipher submitted as an AES candidate. We provide several new results, continuing the research in [SKW+98a, SKW+99b]. 1) We provide new performance numbers, including: faster encryption and decryption on the Pentium Pro/II, faster key setup on the Pentium and Pentium Pro/II in assembly language, large-RAM implementations on 32-bit CPUs, Alpha performance, more implement...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1998