Structural cryptanalysis of SASAS

52Citations
Citations of this article
39Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

In this paper we consider the security of block ciphers which contain alternate layers of invertible S-boxes and affine mappings (there are many popular cryptosystems which use this structure, including the winner of the AES competition, Rijndael). We show that a five-layer scheme with 128-bit plaintexts and 8-bit S-boxes is surprisingly weak against what we call a multiset attack, even when all the S-boxes and affine mappings are key dependent (and thus completely unknown to the attacker). We tested the multiset attack with an actual implementation, which required just 2 16 chosen plaintexts and a few seconds on a single PC to find the 2 17 bits of information in all the unknown elements of the scheme. © 2010 International Association for Cryptologic Research.

Cite

CITATION STYLE

APA

Biryukov, A., & Shamir, A. (2010). Structural cryptanalysis of SASAS. Journal of Cryptology, 23(4), 505–518. https://doi.org/10.1007/s00145-010-9062-1

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free