Lune

CRYPTO2021顶会

Linear Cryptanalysis of FF3-1 and FEA

Tim Beyne

2021年份
11被引次数

摘要

Improved attacks on generic small-domain Feistel ciphers with alternating round tweaks are obtained using linear cryptanalysis. This results in practical distinguishing and message-recovery attacks on the United States format-preserving encryption standard FF3-1 and the South-Korean standards FEA-1 and FEA-2. The data-complexity of the proposed attacks on FF3-1 and FEA-1 is O(Nr/2−1.5)O(N^{r/2 - 1.5}), where N2N^2 is the domain size and rr is the number of rounds. For example, FF3-1 with N=103N = 10^3 can be distinguished from an ideal tweakable block cipher with advantage ≥1/10\ge 1/10 using 2232^{23} encryption queries. Recovering the left half of a message with similar advantage requires 2242^{24} data. The analysis of FF3-1 serves as an interesting real-world application of (generalized) linear cryptanalysis over the group Z/NZ\mathbb{Z}/N\mathbb{Z}.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖