引用本文:宋海欣,范修斌,武传坤,冯登国.流密码算法Grain 的立方攻击.软件学报,2012,23(1):171-176
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 6564次   下载 9872 本文二维码信息
码上扫一扫!
分享到: 微信 更多
流密码算法Grain 的立方攻击
宋海欣1,2, 范修斌1, 武传坤1, 冯登国1
1.中国科学院 软件研究所 信息安全国家重点实验室,北京 100190;2.中国科学院 研究生院,北京 100049
摘要:
Dinur 和Shamir 在2009 年欧洲密码年会上提出了立方攻击的密码分析方法.Grain 算法是欧洲序列密码工程eSTREAM 最终入选的3 个面向硬件实现的流密码算法之一,该算法密钥长度为80 比特,初始向量(initialvector,简称IV)长度为64 比特,算法分为初始化过程和密钥流产生过程,初始化过程空跑160 拍.利用立方攻击方法对Grain 算法进行了分析,在选择IV 攻击条件下,若算法初始化过程空跑70 拍,则可恢复15 比特密钥,并找到了关于另外23 比特密钥的4 个线性表达式;若算法初始化过程空跑75 拍,则可恢复1 比特密钥.
关键词:  eSTREAM 工程  流密码算法  Grain  立方攻击  密钥恢复
DOI:10.3724/SP.J.1001.2012.03983
分类号:
基金项目:国家自然科学基金(60833008, 60902024)
Cube Attack on Grain
SONG Hai-Xin1,2, FAN Xiu-Bin1, WU Chuan-Kun1, FENG Deng-Guo1
1.State Key Laboratory of Information Security, Institute of Software, The Chinese Academy of Sciences, Beijing 100190, China;2.Graduate University, The Chinese Academy of Sciences, Beijing 100049, China
Abstract:
At EUROCRYPT 2009, Dinur and Shamir proposed a new type of algebraic attacks named cube attack. Grain is one of the 3 final hardware-oriented stream ciphers in the eSTREAM portfolio, which takes an 80-bit secret key and a 64-bit initial vector as input and produces its keystream after 160 rounds of initialization. Applying cube attack on Grain with 70 initialization rounds, the study finds that 15-bit secret key can be recovered and can find 4 linear equations on another 23 bits of the secret key. Moreover, 1-bit secret key can be recovered by applying cube attack on Grain with 75 initialization rounds.
Key words:  eSTREAM project  stream cipher  Grain  cube attack  key recovery