Ling Song1,2, Xianrui Qin3, Lei Hu2
Boomerang Connectivity Table Revisited
- 1. Nanyang Technological University, Singapore
- 2. Institute of Information Engineering, CAS, China
- 3. Shandong University, China
Boomerang Connectivity Table Revisited Ling Song 1,2 , Xianrui Qin 3 - - PowerPoint PPT Presentation
Boomerang Connectivity Table Revisited Ling Song 1,2 , Xianrui Qin 3 , Lei Hu 2 1. Nanyang Technological University, Singapore 2. Institute of Information Engineering, CAS, China 3. Shandong University, China FSE 2019 @ Paris Boomerang Attacks
/24
2
/24
https://www.australiathegift.com.au/shop/boomerang-with-stand/
2
/24
NOT always correct
https://www.australiathegift.com.au/shop/boomerang-with-stand/
2
/24
3
/24
πΉπ
1
4
πΉπ πΉπ πΉπ
4
/24
πΉπ
1
4
πΉπ πΉπ πΉπ
4
/24
5
/24
6
/24
7
/24
π π π π¦1 π¦2 π¦3 π§1 π§2 π§3 π§4
π½ πΎ
π
πΎ
π¦4
π½
8
/24
9
/24
9
/24
9
/24
10
/24
10
/24
10
/24
Lower crossing difference Upper crossing difference S-box in E0 S-box in E1 11
/24
11
S-box in E0 S-box in E1 Upper crossing difference Lower crossing difference
/24
12
/24
12
/24
12
/24
13
/24
Lower crossing diff. (πΎ) of A comes from B. Upper crossing diff. (π½β²) of B comes from A. 14
/24
Lower crossing diff. (πΎ) of A comes from B. Upper crossing diff. (π½β²) of B comes from A. 14
/24
Lower crossing diff. (πΎ) of A comes from B. Upper crossing diff. (π½β²) of B comes from A. 14
/24
πππ π‘π’||πΉ0 πππ‘π’ .
πΉ0 πΎ ββ’, β β(πΏ β πΉ1 π).
πΉ1 πΉ0
Pr = 1 Pr = 1
15
/24
16
/24
17
/24
Rd Diff before and after SB βK βK Pr. R1 0,0,0,0, 0,0,0,0, 0,0,0,b, 0,0,0,0 0,0,0,0, 0,0,0,0, 0,0,0,1, 0,0,0,0 0,0,0,0, 0,0,0,0 b,0,0,0, 0,0,0,0 2β2 R2 0,1,0,0, 0,0,0,0, 0,1,0,0, 0,1,0,0 0,8,0,0, 0,0,0,0, 0,8,0,0, 0,8,0,0 0,0,0,0, 0,c,0,0 0,0,0,0, 5,0,0,0 2β2β3 R3 0,0,0,0, 0,0,0,0, 0,0,0,0, 0,0,0,2 0,0,0,0, 0,0,0,0, 0,0,0,0, 0,0,0,3 0,0,0,0, 0,0,0,0 0,0,3,0, 0,0,0,0 2β2 R4 0,0,0,0, 0,0,3,0, 0,0,0,0, 0,0,3,0 0,0,0,0, 0,0,d,0, 0,0,0,0, 0,0,c,0 0,0,0,3, 0,0,0,0 0,0,0,0, 0,0,9,0 2β3β2 R5 0,c,0,0, 0,0,0,0, 0,0,0,4, 0,0,0,0 0,2,0,0, 0,0,0,0, 0,0,0,2, 0,0,0,0 0,0,0,0, 0,0,0,0 0,0,0,0, 2,0,0,0 2β2β2 R6 0,0,0,0, 0,2,0,0, 0,0,0,0, 0,0,0,0 0,0,0,0, 0,1,0,0, 0,0,0,0, 0,0,0,0 0,0,0,0, 0,0,0,d 0,0,0,0, 0,1,0,0 2β2
18
/24
19
/24
20
/24
20
/24
2β31 2β37 πΉπ, π = 2β33.42 ΰ·€ π2 ΰ·€ π2π = 2β109.42
21
/24
22
/24
23