Abstract
In this paper we consider the security ofblo ck ciphers which contain alternate layers ofin vertible S-boxes and affine mappings (there are many popular cryptosystems which use this structure, including the winner ofthe AES competition, Rijndael). We show that a five layer scheme with 128 bit plaintexts and 8 bit S-boxes is surprisingly weak even when all the S-boxes and affine mappings are key dependent (and thus completely unknown to the attacker). We tested the attack with an actual implementation, which required just 216 chosen plaintexts and a few seconds on a single PC to find the 217 bits ofinf ormation in all the unknown elements ofthe scheme.
Author supplied keywords
Cite
CITATION STYLE
Biryukov, A., & Shamir, A. (2001). Structural cryptanalysis of SASAS. In Lecture Notes in Computer Science (Vol. 2045, pp. 394–405). Springer Verlag. https://doi.org/10.1007/3-540-44987-6_24
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.