Securing Color Images Using Two-Square Cipher Associated with Arnold Map

Total Page:16

File Type:pdf, Size:1020Kb

Securing Color Images Using Two-Square Cipher Associated with Arnold Map Multimed Tools Appl DOI 10.1007/s11042-016-3504-1 Securing color images using Two-square cipher associated with Arnold map Sachin Kumar1 · Rajendra K. Sharma1 Received: 27 May 2015 / Revised: 27 February 2016 / Accepted: 29 March 2016 © Springer Science+Business Media New York 2016 Abstract This paper presents an image encryption scheme using modified Two-square cipher associated with Arnold map. The traditional Two-square cipher is modified to make it more secure and applicable on the image data. A new block-based scheme is considered for Arnold map to handle the images of any size. The proposed scheme is structured into a substitution-permutation framework such that it has an excessively huge key space, and the correct decoding is highly sensitive to the correct keys with their correct order. The exper- imental results are given to validate the feasibility and robustness of the proposed scheme. Further, the superiority of the proposed scheme is analyzed by comparing with the related work. Keywords Image encryption · Image decryption · Arnold map · Two-square cipher 1 Introduction Secure transmission of digital images over the open networks is an important area being researched widely. The image data may be subject to various types of passive and active attacks such as interception, modification and substitution etc. The cryptographic functions applied to the images assure the authenticity and privacy of the image data from unautho- rized access and receiving by the intended user only. Since image data has some intrinsic characteristics such as bulk data, high data redundancy and strong correlation of adjacent pixels, the traditional algorithms like Data Encryption Standard (DES), Advanced Encryp- Sachin Kumar [email protected] Rajendra K. Sharma [email protected] 1 Department of Mathematics, Indian Institute of Technology Delhi, Hauz Khas, New Delhi, 110016, India Multimed Tools Appl tion Standard (AES) and Rivest Shamir Adleman (RSA) may not be ideal candidates for real-time image encryption as demanding the high computational power [17]. Thus, study of image encryption is necessary to have the techniques satisfying the requirements and characteristics of the image data. In the literature, several methods are developed to han- dle the image data based on various design techniques and primitives in combination. The fourier, discrete cosine, wavelet, gyrator, affine, arnold transforms, and the chaotic maps etc. are some of the common primitives used to determine the image encryption methods [1, 3, 5–19, 21–26]. In [5, 12, 15, 21, 23, 24], the image encoding and decoding methods are presented based on Arnold map associated with other different primitives. Guo et al. [5] proposed an image encryption method, where a color image in Red-Green-Blue (RGB) space is first trans- formed to intensity-hue-saturation (IHS) space and then encrypted in IHS space by using Arnold map and discrete fractional random transform. Liu et al. [15] presented a technique, where the pixel values of RGB components of the original image are scrambled by Arnold Map, and then translated using a matrix defined by a random angle. Further, the discrete cosine transform is employed to the scrambled and translated image. Sui and Gao [21]pre- sented the application of Arnold map associated with chaotic maps and gyrator transform. All these mentioned schemes [5, 15, 21] bring the nice application of Arnold map in con- junction with other primitives but these are limited to handle the images of square size, and also have the key sensitivity on the correct keys not on their arrangements. Tang and Zhang [23] used Arnold map with three random strategies to define a nice scheme for the images of any size. In the first strategy, image is divided into random overlapping blocks of square size followed by generating random iterative numbers in the second strategy. In the third strategy, a random encryption order is obtained for processing the overlapping blocks by Arnold map. All these strategies are governed by separate keys. In Tang and Zhang’s scheme, the random division can result in adjacent squares having overlapping regions where some pixels in overlapping regions can be processed several times by Arnold map. Since Arnold map is periodic in nature, these overlapping regions can have reduced effect or even no effect of iteration numbers. Thus, iteration numbers requires to be chosen carefully such that periodicity is not exhaust. Recently, Tang et al. [24] have proposed an efficient image encryption scheme using block shuffling and chaotic map, where Arnold map is exploited to generate a set of secret matrices used to make final encryption. The schemes [23, 24] have abilities to handle the images of any size and also the key sensitivity on the arrangements of the keys, but lack having the robustness validation against the many desired properties such as correlation, diffusion characteristics, resistance against cryptanalytical attacks etc. There are several methods for image encryption using Arnold map with different primi- tives in combination but some of these lack in having good security against brute force attack (i.e., huge key space), and some in having key sensitivity on the arrangements of the keys. None of these has complete validation of robustness as does not provide security analysis against attacks like differential, known plaintext, chosen plaintext and chosen ciphertext. The high security of the image data in transmitting over the open network has become an important agenda of the present era. This motivates us to design an image encryption scheme having high security and complete validation of robustness against the cryptana- lytical attacks. To meet our aim, we explore the combination of widely used Arnold map with a new primitive from the books of classical cryptography, i.e., traditional Two-square cipher. The traditional Two-square cipher is modified to make it applicable on images and more secure. A new block-based scheme for Arnold map is also designed to have no size Multimed Tools Appl limitation of the input images, which is combined with modified Two-square finally to have encrypted images. Further, the experimental results are conduced to validate the strength of the scheme against statistical analysis and attacks including its time complexity, key sen- sitivity and space analysis. We are able to have an image encryption scheme which has a complete validation of robustness and an extensively huge key space with security not only in terms of the keys but also in their arrangements. The scheme has ability to resist most of the statistical and cryptanalytical attacks. The proposed scheme is also compared with the related image encryption schemes. Compared to the related schemes, the proposed scheme is highly robust and secure, and has better performance. The rest of this paper is organized as follows. In Section 2, the traditional Two-square cipher and Arnold map are discussed briefly. Section 3 describes the proposed encryption and decryption algorithm for color images. Section 4 presents the experimental results and robustness validation. In Section 5, key sensitivity and key space are analyzed. In Section 6, the proposed scheme is compared with the related work. Section 7 draws the concluding remarks. 2 Traditional Two-square cipher and Arnold map This section briefly discusses the encryption algorithms using the traditional Two-square cipher and the Arnold map. 2.1 Traditional Two-square cipher The Two-square cipher was developed to have a classical system stronger than Playfair cipher and less cumbersome than Four-square cipher. It is a digraphic system, where two letters of plaintext (in English) are replaced with two letters of ciphertext in each encipher- ment. It consists two 5 by 5 squares either next to each other (horizontal Two-square) or one top of each other (vertical Two-square). Normally, both squares contain mixed sequences preferably using two different keywords. An example of horizontal and vertical Two-square using keywords “ENCRYPT” and “DECRYPT” is given in Fig. 1. Fig. 1 An illustration: a Horizontal Two-square; b Vertical Two-square Multimed Tools Appl For encipherment or decipherment, first the text message is divided into digraphs. The following rule is used for enciphering the plaintext digraph p1p2 into the ciphertext digraph c1c2. a) Locate the first letter of the digraph within the first square (left/top) and the second letter in the second square (right/bottom) b) Form the rectangle with these two letters at from the opposite corners c) Select the ciphertext or plaintext digraph from the other two corners of the rectangle In horizontal Two-square, if the letters of a digraph to be enciphered are in same row then these are replaced with the same letters in reverse order. In vertical Two-square, whenever the letters to be enciphered are in same column, however, the letters become their own equivalents. In Two-square cipher, the decipherment is handled in exactly the similar way as encipherment. Figure 2 illustrates the encipherment using horizontal and vertical Two- square as given in Fig. 1. The digraphs in ciphertext which are same as plaintext or in reverse are called transparen- cies or reverse transparencies respectively. The traditional Two-square cipher has weakness that in long run, about 20 % of the digraphs will be transparencies. We propose some mod- ifications in traditional Two-square cipher to remove this weakness as well as to make it suitable for encrypting the images. 2.2 Arnold map It is also known as cat map face, which was proposed by V. Arnold in the research of ergodic theory [2], and is defined as x 11 x = (mod 1) (1) y 12 y where the point (x, y) in unit square is transformed to another point (x,y). In respect to the image of size N × N, the Arnold map is defined as x 11 x = (mod N) (2) y 12 y The pixel at position (x, y) in the original image is mapped to the position (x,y) after one iteration of Arnold map in (2).
Recommended publications
  • Integral Cryptanalysis on Full MISTY1⋆
    Integral Cryptanalysis on Full MISTY1? Yosuke Todo NTT Secure Platform Laboratories, Tokyo, Japan [email protected] Abstract. MISTY1 is a block cipher designed by Matsui in 1997. It was well evaluated and standardized by projects, such as CRYPTREC, ISO/IEC, and NESSIE. In this paper, we propose a key recovery attack on the full MISTY1, i.e., we show that 8-round MISTY1 with 5 FL layers does not have 128-bit security. Many attacks against MISTY1 have been proposed, but there is no attack against the full MISTY1. Therefore, our attack is the first cryptanalysis against the full MISTY1. We construct a new integral characteristic by using the propagation characteristic of the division property, which was proposed in 2015. We first improve the division property by optimizing a public S-box and then construct a 6-round integral characteristic on MISTY1. Finally, we recover the secret key of the full MISTY1 with 263:58 chosen plaintexts and 2121 time complexity. Moreover, if we can use 263:994 chosen plaintexts, the time complexity for our attack is reduced to 2107:9. Note that our cryptanalysis is a theoretical attack. Therefore, the practical use of MISTY1 will not be affected by our attack. Keywords: MISTY1, Integral attack, Division property 1 Introduction MISTY [Mat97] is a block cipher designed by Matsui in 1997 and is based on the theory of provable security [Nyb94,NK95] against differential attack [BS90] and linear attack [Mat93]. MISTY has a recursive structure, and the component function has a unique structure, the so-called MISTY structure [Mat96].
    [Show full text]
  • Division Property: Efficient Method to Estimate Upper Bound of Algebraic Degree
    Division Property: Efficient Method to Estimate Upper Bound of Algebraic Degree Yosuke Todo1;2 1 NTT Secure Platform Laboratories, Tokyo, Japan [email protected] 2 Kobe University, Kobe, Japan Abstract. We proposed the division property, which is a new method to find integral characteristics, at EUROCRYPT 2015. In this paper, we expound the division property, its effectiveness, and follow-up results. Higher-Order Differential and Integral Cryptanalyses. After the pro- posal of the differential cryptanalysis [1], many extended cryptanalyses have been proposed. The higher-order differential cryptanalysis is one of such extensions. The concept was first introduced by Lai [6] and the advantage over the classical differential cryptanalysis was studied by Knudsen [4]. Assuming the algebraic degree of the target block cipher Ek is upper-bounded by d for any k, the dth order differential is always constant. Then, we can distinguish the target cipher Ek as ideal block ciphers because it is unlikely that ideal block ciphers have such property, and we call this property the higher-order differential characteristics in this paper. The similar technique to the higher-order differential cryptanalysis was used as the dedicated attack against the block cipher Square [3], and the dedicated attack was later referred to the square attack. In 2002, Knudsen and Wagner formalized the square attack as the integral cryptanalysis [5]. In the integral cryptanalysis, attackers first prepare N chosen plaintexts. If the XOR of all cor- responding ciphertexts is 0, we say that the cipher has an integral characteristic with N chosen plaintexts. The integral characteristic is found by evaluating the propagation of four integral properties: A, C, B, and U.
    [Show full text]
  • Performance Analysis of Advanced Encryption Standard (AES) S-Boxes
    International Journal of Recent Technology and Engineering (IJRTE) ISSN: 2277-3878, Volume-9, Issue-1, May 2020 Performance Analysis of Advanced Encryption Standard (AES) S-boxes Eslam w. afify, Abeer T. Khalil, Wageda I. El sobky, Reda Abo Alez Abstract : The Advanced Encryption Standard (AES) algorithm The fundamental genuine data square length for AES is 128 is available in a wide scope of encryption packages and is the bits that as it might; the key length for AES possibly 128, single straightforwardly accessible cipher insisted by the 192, or 256 bits [2, 3]. The conversation is focused on National Security Agency (NSA), The Rijndael S-box is a Rijndael S-Box yet a huge amount of the trade can in like substitution box S-Box assumes a significant job in the AES manner be associated with the ideal security of block cipher algorithm security. The quality of S-Box relies upon the plan and mathematical developments. Our paper gives an outline of AES and the objective of the cryptanalysis. As follows the paper S-Box investigation, the paper finds that algebraic attack is the is sorted out: Section II gives a detailed analysis of the most security gap of AES S-Box, likewise give a thought structure of the AES. Section III scope in the cryptanalysis regarding distinctive past research to improve the static S- study of algebraic techniques against block ciphers, gives a confines that has been utilized AES, to upgrade the quality of detailed analysis of S-Box algebraic structure and AES Performance by shocking the best S-box.
    [Show full text]
  • Optimization and Guess-Then-Solve Attacks in Cryptanalysis
    Optimization and Guess-then-Solve Attacks in Cryptanalysis Guangyan Song A dissertation submitted in partial fulfillment of the requirements for the degree of Doctor of Philosophy of University College London. Department of Computer Science University College London December 4, 2018 2 I, Guangyan Song, confirm that the work presented in this thesis is my own. Where information has been derived from other sources, I confirm that this has been indicated in the work. Abstract In this thesis we study two major topics in cryptanalysis and optimization: software algebraic cryptanalysis and elliptic curve optimizations in cryptanalysis. The idea of algebraic cryptanalysis is to model a cipher by a Multivariate Quadratic (MQ) equation system. Solving MQ is an NP-hard problem. However, NP-hard prob- lems have a point of phase transition where the problems become easy to solve. This thesis explores different optimizations to make solving algebraic cryptanalysis problems easier. We first worked on guessing a well-chosen number of key bits, a specific opti- mization problem leading to guess-then-solve attacks on GOST cipher. In addition to attacks, we propose two new security metrics of contradiction immunity and SAT immunity applicable to any cipher. These optimizations play a pivotal role in recent highly competitive results on full GOST. This and another cipher Simon, which we cryptanalyzed were submitted to ISO to become a global encryption standard which is the reason why we study the security of these ciphers in a lot of detail. Another optimization direction is to use well-selected data in conjunction with Plaintext/Ciphertext pairs following a truncated differential property.
    [Show full text]
  • 1. Classical Cryptography
    1. Classical Cryptography Some Simple Cryptosystems • Shift Cipher, • Substitution Cipher, • Affine Cipher, • Vigenere Cipher, • Hill Cipher, • Permutation Cipher, • Stream Cipher Modular Arithmetic, Number theory, and Group Cryptanalysis The RSA Cryptosystem 1 Classical Cryptography Definition 1.1: A cryptosystem is a five-tuple (P, C, H, E, D), where the following conditions are satisfied: 1. P is a finite set of possible plaintexts 2. C is a finite set of possible ciphertexts 3. H the keyspace, is a finite set of possible keys 4. For each K H, there is an encryption rule eK E : P C and a corresponding decryption rule dK D: C P such that x C, dK (eK(x)) = x Oscar x y x Alice Encrypter Decrypter Bob Secure chanel K Key source 2 Modular Arithmetic Definition 1.2: Suppose a and b are integers, and m is positive integer. Then we write a b (mod m) if m divides b-a. • a b mod m if and only if (a-b) = km for some k •Zm the equivalence class under mod m • Canonical form Zm = {0,1,2,…,m-1}, we use the positive remainder as the standard representation. • -1 m -1 mod m • (Zm, +, 0) is a Group . + is closed . Associative: (a + b) + c = a + (b + c) . Commutative: a + b = b + a (abelian group) . 0 is the identity for +: a + 0 = a + 0 = a . Additive inverse: (-a) + a = a + (-a) = 0 3 Modular Arithmetic • (Zm, +, , 0, 1) is a Ring . +, are closed . +, are associative and commutative (abelian ring) . Operation distributes over +: a (b + c) = a b + a c .
    [Show full text]
  • Discrete Square Roots Cryptosystems Rabin Cryptosystem
    CHAPTER 6: OTHER CRYPTOSYSTEMS and BASIC CRYPTOGRAPHY PRIMITIVES A large number of interesting and important cryptosystems have already been designed. In this chapter we present several other of them in order to illustrate other principles and techniques that can be used to design cryptosystems. Part VI At first, we present several cryptosystems security of which is based on the fact that computation of square roots and discrete logarithms is in general infeasible in some Public-key cryptosystems, II. Other cryptosystems, security, PRG, hash groups. functions Secondly, we discuss one of the fundamental questions of modern cryptography: when can a cryptosystem be considered as (computationally) perfectly secure? In order to do that we will: discuss the role randomness play in the cryptography; introduce the very fundamental definitions of perfect security of cryptosystem present some examples of perfectly secure cryptosystems. Finally, we discuss in some details such important cryptography primitives as pseudo-random number generators and hash functions prof. Jozef Gruska IV054 6. Public-key cryptosystems, II. Other cryptosystems, security, PRG, hash functions 2/66 DISCRETE SQUARE ROOTS CRYPTOSYSTEMS RABIN CRYPTOSYSTEM Let Blum primes p, q are kept secret, and let the Blum integer n = pq be the public key. Encryption: of a plaintext w < n c = w 2 (mod n) Decryption: -briefly It is easy to verify (using Euler’s criterion which says that if c is a quadratic residue (p 1)/2 modulo p, then c − 1 (mod p),) that DISCRETE SQUARE ROOTS CRYPTOSYSTEMS ≡ c(p+1)/4mod p and c(q+1)/4mod q ± ± p+1 p 1 are two square roots of c modulo p and q.
    [Show full text]
  • On Constructions of MDS Matrices from Circulant-Like Matrices for Lightweight Cryptography
    On Constructions of MDS Matrices From Circulant-Like Matrices For Lightweight Cryptography Technical Report No. ASU/2014/1 Dated : 14th February, 2014 Kishan Chand Gupta Applied Statistics Unit Indian Statistical Institute 203, B. T. Road, Kolkata 700108, INDIA. [email protected] Indranil Ghosh Ray Applied Statistics Unit Indian Statistical Institute 203, B. T. Road, Kolkata 700108, INDIA. indranil [email protected] On Constructions of MDS Matrices From Circulant-Like Matrices For Lightweight Cryptography Kishan Chand Gupta and Indranil Ghosh Ray Applied Statistics Unit, Indian Statistical Institute. 203, B. T. Road, Kolkata 700108, INDIA. [email protected], indranil [email protected] Abstract. Maximum distance separable (MDS) matrices have applications not only in coding theory but are also of great importance in the design of block ciphers and hash functions. It is highly nontrivial to find MDS matrices which could be used in lightweight cryptography. In a SAC 2004 paper, Junod et. al. constructed a new class of efficient MDS matrices whose submatrices were circulant matrices and they coined the term circulating-like matrices for these new class of matrices which we rename as circulant-like matrices. In this paper we study this construction and propose efficient 4 × 4 and 8 × 8 circulant-like MDS matrices. We prove that such d × d circulant-like MDS matrices can not be involutory or orthogonal which are good for designing SPN networks. Although these matrices are efficient, but the inverse of such matrices are not guaranteed to be efficient. Towards this we design a new type of circulant- like MDS matrices which are by construction involutory.
    [Show full text]
  • Multiset-Algebraic Cryptanalysis of Reduced Kuznyechik, Khazad, and Secret Spns
    IACR Transactions on Symmetric Cryptology ISSN 2519-173X, Vol. 2016, No. 2, pp. 226–247. DOI:10.13154/tosc.v2016.i2.226-247 Multiset-Algebraic Cryptanalysis of Reduced Kuznyechik, Khazad, and secret SPNs Alex Biryukov1, Dmitry Khovratovich2 and Léo Perrin3 1 Interdisciplinary Centre for Security, Reliability and Trust (SnT), Computer Science and Communications Research Unit (CSC), University of Luxembourg, Luxembourg, Luxembourg [email protected] 2 University of Luxembourg, Luxembourg, Luxembourg [email protected] 3 Interdisciplinary Centre for Security, Reliability and Trust (SnT), Computer Science and Communications Research Unit, University of Luxembourg, Luxembourg, Luxembourg [email protected] Abstract. We devise the first closed formula for the number of rounds of a blockcipher with secret components so that these components can be revealed using multiset, algebraic-degree, or division-integral properties, which in this case are equivalent. Using the new result, we attack 7 (out of 9) rounds of Kuznyechik, the recent Russian blockcipher standard, thus halving its security margin. With the same technique we attack 6 (out of 8) rounds of Khazad, the legacy 64-bit blockcipher. Finally, we show how to cryptanalyze and find a decomposition of generic SPN construction for which the inner-components are secret. All the attacks are the best to date. Keywords: Generic SPN · Algebraic attack · Multi-set · Integral · Division property · Kuznyechik · Khazad 1 Introduction 1.1 Multiset, integrals, division, and algebraic degree Multiset attacks originated in the late 1990s with application to byte-oriented block- ciphers [BS01] and are also known as Square [DKR97], integral [KW02], and satura- tion [Luc01] attacks. For years, they remained the most efficient method to attack AES [FKL+00, DF13], Camellia, and other popular designs.
    [Show full text]
  • New Directions in Cryptanalysis of Block Ciphers
    Journal of Computer Science 5 (12): 1091-1094, 2009 ISSN 1549-3636 © 2009 Science Publications New Directions in Cryptanalysis of Block Ciphers Davood RezaeiPour and Mohamad Rushdan Md Said Institute for Mathematical Research, University Putra Malaysia, 43400 UPM Serdang, Selangor Darul Ehsan, Malaysia Abstract: Problem statement: The algebraic expression of the Advanced Encryption Standard (AES) RIJNDAEL S-box involved only 9 terms. The selected mapping for RIJNDAEL S-box has a simple algebraic expression. This enables algebraic manipulations which can be used to mount interpolation attack. Approach: The interpolation attack was introduced as a cryptanalytic attack against block ciphers. This attack is useful for cryptanalysis using simple algebraic functions as S-boxes. Results: In this study, we presented an improved AES S-box with good properties to improve the complexity of AES S-box algebraic expression with terms increasing to 255. Conclusion: The improved S-box is resistant against interpolation attack. We can develop the derivatives of interpolation attack using the estimations of S-box with less nonlinearity. Key words: Block cipher, AES, S-box, interpolation attack, Lagrange interpolation formula INTRODUCTION In this article, we first describe the main parts of AES (RIJNDAEL) which consists of the individual The interpolation attack is a technique for attacking transformations and AES S-box. We will introduce the block ciphers built from simple algebraic functions. A interpolation attack with considering of the points of block cipher algorithm may not include any algebraic weakness and strength in AES S-box. Finally, we will property that can be efficiently distinguishable, since an discuss the manner of doing interpolation attack using the different representations of AES S-box.
    [Show full text]
  • On the Interpolation Attacks on Block Ciphers 111
    On the Interp olation Attacks on Blo ck Ciphers A.M. Youssef and G. Gong Center for Applied Cryptographic Research Department of Combinatorics and Optimization UniversityofWaterlo o, Waterlo o, ON N2L 3G1 fa2youssef, [email protected] o.ca Abstract. The complexityofinterp olation attacks on blo ck ciphers de- p ends on the degree of the p olynomial approximation and/or on the numb er of terms in the p olynomial approximation expression. In some situations, the round function or the S-b oxes of the blo ck cipher are expressed explicitly in terms of algebraic function, yet in many other o ccasions the S-b oxes are expressed in terms of their Bo olean function representation. In this case, the cryptanalyst has to evaluate the algebraic description of the S-b oxes or the round function using the Lagrange in- terp olation formula. A natural question is what is the e ect of the choice of the irreducible p olynomial used to construct the nite eld on the degree of the resulting p olynomial . Another question is whether or not there exists a simple linear transformation on the input or output bits of the S-b oxes (or the round function) such that the resulting p olynomial has a less degree or smaller numb er of non-zero co ecients. In this pap er we give an answer to these questions. We also present an explicit relation between the Lagrange interp olation formula and the Galois Field Fourier Transform. Keywords: Blo ck cipher, cryptanalysis, interp olation attack, nite elds, Ga- lois Field Fourier Transform 1 Intro duction Gong and Golomb[7]intro duced a new criterion for the S-b ox design.
    [Show full text]
  • Integral Cryptanalysis
    Chapter 5 - integral cryptanalysis. James McLaughlin 1 Introduction. The history of integral cryptanalysis is a little complicated, and the most important papers to study regarding it are not in fact the ones in which it was first defined. We give a brief recap here: In 1997, Daemen, Knudsen, and Rijmen published a paper [3] describing a new cipher. This cipher, SQUARE, was a forerunner of Rijndael [10], the eventual AES, and was designed using the same wide trail strategy to provide security against differential and linear cryptanalysis. However, while working on the paper, the authors discovered a new kind of chosen-plaintext attack which broke six rounds of SQUARE. Since SQUARE had originally been designed with this many rounds, the authors were forced to add more rounds and to publish details of the attack as well as the cipher. The attack - not at the time given a name, but later referred to as the “Square attack” - did not scale well to attack more rounds, and also bore certain similarities to linear and differential cryptanalysis. Because of this, and because of the level of diffusion stipulated by the wide trail strategy, the authors decided that only two extra rounds needed to be added to the cipher to defeat the attack. Although specific to SQUARE, the similarities between SQUARE and Rijndael, as also the cipher CRYPTON [8], meant that it could easily be adapted to these ciphers. Again, it broke six rounds of Rijndael, in an attack much the same as the attack against SQUARE, and the creator of CRYPTON conjectured [8] that it would not break more than six rounds of that either.
    [Show full text]
  • Impossible Differential Cryptanalysis of ARIA and Camellia
    Impossible Di®erential Cryptanalysis of ARIA and Camellia Wenling Wu, Wentao Zhang, Dengguo Feng State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100080, P. R. China [email protected] Abstract. This paper studies the security of the block ciphers ARIA and Camellia against impossible di®erential cryptanalysis. Our work im- proves the best impossible di®erential cryptanalysis of ARIA and Camel- lia known so far. The designers of ARIA expected no impossible di®eren- tials exist for 4-round ARIA. However, we found some nontrivial 4-round impossible di®erentials, which may lead to a possible attack on 6-round ARIA. Moreover, we found some nontrivial 8-round impossible di®er- entials for Camellia, whereas only 7-round impossible di®erentials were previously known. By using the 8-round impossible di®erentials, we pre- sented an attack on 12-round Camellia without F L=F L¡1 layers. Key words. Block cipher, ARIA, Camellia, Data complexity, Time com- plexity, Impossible Di®erential Cryptanalysis. 1 Introduction Both ARIA[1] and Camellia[2] support 128-bit block size and 128-,192-, and 256- bit key lengths, i.e. the same interface speci¯cations as the Advanced Encryption Standard(AES). Camellia was jointly developed in 2000 by Nippon Telegraph and Telephone Corporation (NTT) and Mitsubishi Electric Corporation (Mit- subishi). It has now been selected as an international standard by ISO/IEC, and also been adopted by cryptographic evaluation projects such as NESSIE and CRYPTREC, as well as the standardization activities at IETF. It means Camellia gradually become one of the most worldwide used block ciphers.
    [Show full text]