Probabilistic Slide Cryptanalysis and Its Applications to LED-64 and Zorro
Hadi Soleimany
Department of Information and Computer Science, Aalto University School of Science, Finland
FSE 2014
1 / 21
Probabilistic Slide Cryptanalysis and Its Applications to LED-64 and - - PowerPoint PPT Presentation
Probabilistic Slide Cryptanalysis and Its Applications to LED-64 and Zorro Hadi Soleimany Department of Information and Computer Science, Aalto University School of Science, Finland FSE 2014 1 / 21 Outline Introduction Slide Cryptanalysis
1 / 21
2 / 21
3 / 21
4 / 21
5 / 21
5 / 21
6 / 21
6 / 21
6 / 21
k
6 / 21
k
6 / 21
k
6 / 21
7 / 21
7 / 21
8 / 21
9 / 21
10 / 21
11 / 21
◮ But it is limited to the ciphers with identical rounds. 11 / 21
◮ But it is limited to the ciphers with identical rounds.
11 / 21
◮ But it is limited to the ciphers with identical rounds.
◮ But there exists a lower bound for active S-boxes and it
11 / 21
◮ But it is limited to the ciphers with identical rounds.
◮ But there exists a lower bound for active S-boxes and it
11 / 21
◮ But it is limited to the ciphers with identical rounds.
◮ But there exists a lower bound for active S-boxes and it
◮ But usually it is not a realistic model. 11 / 21
◮ But it is limited to the ciphers with identical rounds.
◮ But there exists a lower bound for active S-boxes and it
◮ But usually it is not a realistic model.
11 / 21
◮ But it is limited to the ciphers with identical rounds.
◮ But there exists a lower bound for active S-boxes and it
◮ But usually it is not a realistic model.
◮ But its application is limited to involutional block ciphers. 11 / 21
◮ But it is limited to the ciphers with identical rounds.
◮ But there exists a lower bound for active S-boxes and it
◮ But usually it is not a realistic model.
◮ But its application is limited to involutional block ciphers.
11 / 21
12 / 21
12 / 21
s
12 / 21
s
s
12 / 21
13 / 21
13 / 21
13 / 21
13 / 21
13 / 21
i=1 2−pi
14 / 21
15 / 21
16 / 21
16 / 21
16 / 21
16 / 21
16 / 21
16 / 21
16 / 21
5 ⊕ P′
5 ⊕ X ′S 1
5 ⊕ X A 1
5 ⊕ X ′R 1
16 ⊕ X ′A 12
16 ⊕ X ′R 12
16 ⊕ X ′M 12
17 / 21
[G´ erard et al 13]
erard et al 13]
[Guo et al 13]
[Isobe et al 12]
[Dinur et al 13]
[Dinur et al 14]
[Dinur et al 14]
[Dinur et al 13]
18 / 21
19 / 21
20 / 21
21 / 21