Result: Algebraic Degree Estimation of Block Ciphers Using Randomized Algorithm; Upper-Bound Integral Distinguisher

Title:
Algebraic Degree Estimation of Block Ciphers Using Randomized Algorithm; Upper-Bound Integral Distinguisher
Source:
International Journal on Cryptography and Information Security. 6:09-29
Publisher Information:
Academy and Industry Research Collaboration Center (AIRCC), 2016.
Publication Year:
2016
Document Type:
Academic journal Article
ISSN:
1839-8626
DOI:
10.5121/ijcis.2016.6402
DOI:
10.5281/zenodo.1199863
DOI:
10.5281/zenodo.1199864
Rights:
CC BY
Accession Number:
edsair.doi.dedup.....8df2d6a22d7148bccb4ec4ae2e9d28af
Database:
OpenAIRE

Further Information

Integral attack is a powerful method to recover the secret key of block cipher by exploiting a characteristic that a set of outputs after several rounds encryption has ( integral distinguisher). Recently, Todo proposed a new algorithm to construct integral distinguisher with division property. However, the existence of integral distinguisher which holds in additional rounds can not be denied by the algorithm. On the contrary, we take an approach to obtain the number of rounds which integral distinguisher does not hold ( upper-bound integral distinguisher). The approach is based on algebraic degree estimation. We execute a random search for a term which has a degree equals the number of all inputted variables. We propose an algorithm and apply it to PRESENT and RECTANGLE. Then, we confirm that there exists no 8-round integral distinguisher in PRESENT and no 9-round integral distinguisher in RECTANGLE. From the facts, integral attack for more than 11-round and 13-round of PRESENT and RECTANGLE is infeasible, respectively.