Abstract
In this paper we consider the security of block ciphers which contain alternate layers of invertible S-boxes and affine mappings (there are many popular cryptosystems which use this structure, including the winner of the AES competition, Rijndael). We show that a five-layer scheme with 128-bit plaintexts and 8-bit S-boxes is surprisingly weak against what we call a multiset attack, even when all the S-boxes and affine mappings are key dependent (and thus completely unknown to the attacker). We tested the multiset attack with an actual implementation, which required just 2 16 chosen plaintexts and a few seconds on a single PC to find the 2 17 bits of information in all the unknown elements of the scheme. © 2010 International Association for Cryptologic Research.
Author supplied keywords
Cite
CITATION STYLE
Biryukov, A., & Shamir, A. (2010). Structural cryptanalysis of SASAS. Journal of Cryptology, 23(4), 505–518. https://doi.org/10.1007/s00145-010-9062-1
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.