New Slide Attacks on Almost Self-similar Ciphers
Orr Dunkelman, Nathan Keller, Noam Lasry, Adi Shamir
Abstract
The slide attack is a powerful cryptanalytic tool which has the unusual property that it can break iterated block ciphers with a complexity that does not depend on their number of rounds. However, it requires complete self similarity in the sense that all the rounds must be identical. While this can be the case in Feistel structures, this rarely happens in SP networks since the last round must end with an additional post-whitening subkey. In addition, in many SP networks the final round has additional asymmetries -- for example, in AES the last round omits the MixColumns operation. Such asymmetry in the last round can make it difficult to utilize most of the advanced tools which were developed for slide attacks, such as deriving from one slid pair additional slid pairs by repeatedly re-encrypting their ciphertexts.
In this paper we overcome this "last round problem" by developing four new types of slide attacks. We demonstrate their power by applying them to many types of AES-like structures (with and without linear mixing in the last round, with known or secret S-boxes, with 1,2 and 3 periodicity in their subkeys, etc). In most of these cases, the time complexity of our attack is close to , which is the smallest possible complexity for slide attacks. Our new slide attacks have several unique properties: The first attack uses slid sets in which each plaintext from the first set forms a slid pair with some plaintext from the second set, but without knowing the exact correspondence. The second attack makes it possible to create from several slid pairs an exponential number of new slid pairs which form a hypercube spanned by the given pairs. The third attack has the unusual property that it is always successful, and the fourth attack can use known messages instead of chosen messages, with only slightly higher time complexity.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a6da21cc-16bf-4a65-bc09-eecc53da8d3eRelated papers
- Linear Cryptanalysis of FF3-1 and FEATim BeyneCRYPTO 2021 · 11 citations
- New Representations of the AES Key ScheduleGaëtan Leurent, Clara PernotEUROCRYPT 2021 · 33 citations
- The Retracing Boomerang AttackOrr Dunkelman, Nathan Keller, Eyal Ronen, Adi ShamirEUROCRYPT 2020 · 53 citations
- New Collision Attacks on Round-Reduced SHA-512Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian et al.CRYPTO 2025 · 4 citations
- Feistel-Like Structures Revisited: Classification and CryptanalysisBing Sun, Zejun Xiang, Zhengyi Dai, Guoqiang Liu et al.CRYPTO 2024 · 5 citations
