Abstract
We present new attacks on the Feistel network, where each round function consists of a subkey XOR, S-boxes, and then a linear transformation (i.e., an SP round function). Our techniques are based largely on what they call the rebound attacks. As a result, our attacks work most effectively when the S-boxes have a "good" differential property (like the inverse function x → x-1 in the finite field) and when the linear transformation has an "optimal" branch number (i.e., a maximum distance separable matrix). We first describe known-key distinguishers on such Feistel block ciphers of up to 11 rounds, increasing significantly the number of rounds from previous work. We then apply our distinguishers to the Matyas-Meyer-Oseas and Miyaguchi-Preneel modes in which the Feistel ciphers are used, obtaining collision and half-collision attacks on these hash functions. © 2011 Springer-Verlag.
Author supplied keywords
Cite
CITATION STYLE
Sasaki, Y., & Yasuda, K. (2011). Known-key distinguishers on 11-round Feistel and collision attacks on its hashing modes. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6733 LNCS, pp. 397–415). Springer Verlag. https://doi.org/10.1007/978-3-642-21702-9_23
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.