Two Versions of the Stream Cipher Snow a Thesis Submitted to the Graduate School of Natural and Applied Sciences of Middle East
Total Page:16
File Type:pdf, Size:1020Kb
TWO VERSIONS OF THE STREAM CIPHER SNOW A THESIS SUBMITTED TO THE GRADUATE SCHOOL OF NATURAL AND APPLIED SCIENCES OF MIDDLE EAST TECHNICAL UNIVERSITY BY ERDEM YILMAZ IN PARTIAL FULFILLMENT OF THE REQUIREMENTS FOR THE DEGREE OF MASTER OF SCIENCE IN ELECTRICAL AND ELECTRONICS ENGINEERING DECEMBER 2004 Approval of the Graduate School of Natural and Applied Sciences _________________________ Prof. Dr. Canan Özgen Director I certify that this thesis satisfies all the requirements as a thesis for the degree of Master of Science. _________________________ Prof. Dr. İsmet Erkmen Head of Department This is to certify that we have read this thesis and that in our opinion it is fully adequate, in scope and quality, as a thesis for the degree of Master of Science. _________________________ Assoc. Prof. Dr. Melek D. Yücel Supervisor Examining Committee Members Prof. Dr. Yalçın Tanık (METU,EE)________________________ Assoc. Prof. Dr. Melek D. Yücel (METU,EE)________________________ Prof. Dr. Murat Aşkar (METU,EE)________________________ Assoc. Prof. Dr. Ferruh Özbudak (METU,MATH)________________________ Asst. Prof. Dr. A. Özgür Yılmaz (METU,EE)________________________ I hereby declare that all information in this document has been obtained and presented in accordance with academic rules and ethical conduct. I also declare that, as required by these rules and conduct, I have fully cited and referenced all material and results that are not original to this work. Name, Last Name: Erdem Yılmaz Signature : iii ABSTRACT TWO VERSIONS OF THE STREAM CIPHER SNOW Yılmaz, Erdem M.Sc., Department of Electrical and Electronics Engineering Supervisor: Assoc. Prof. Dr. Melek D. Yücel December 2004, 60 pages Two versions of SNOW, which are word-oriented stream ciphers proposed by P. Ekdahl and T. Johansson in 2000 and 2002, are studied together with cryptanalytic attacks on the first version. The reported attacks on SNOW1.0 are the “guess-and- determine attack”s by Hawkes and Rose and the “distinguishing attack” by Coppersmith, Halevi and Jutla in 2002. A review of the distinguishing attack on SNOW1.0 is given using the approach made by the designers of SNOW in 2002 on another cipher, SOBER-t32. However, since the calculation methods for the complexities of the attack are different, the values found with the method of the designers of SNOW are higher than the ones found by Coppersmith, Halevi and Jutla. The correlations in the finite state machine that make the distinguishing attack possible and how these correlations are affected by the operations in the finite state machine are investigated. Since the substitution boxes (S-boxes) play an important iv role in destroying the correlation and linearity caused by Linear Feedback Shift Register, the s-boxes of the two versions of SNOW are examined for the criteria of Linear Approximation Table (LAT), Difference Distribution Table (DDT) and Auto- correlation Table distributions. The randomness tests are performed using NIST statistical test suite for both of the ciphers. The results of the tests are presented. Keywords: Stream Cipher, SNOW, S-box, Distinguishing Attack, Randomness Tests v ÖZ SNOW AKAN ŞİFRESİNİN İKİ UYARLAMASI Yılmaz, Erdem Yüksek Lisans, Elektrik ve Elektronik Mühendisliği Bölümü Tez yöneticisi: Doç. Dr. Melek D. Yücel Aralık 2004, 60 sayfa P. Ekdahl ve T. Johansson tarafından 2000 ve 2002 yıllarında önerilen ve kelime odaklı akan şifrelerden olan SNOW’un iki uyarlaması ve birinci uyarlamasına yapılmış kriptanaliz atakları üzerinde çalışılmıştır. SNOW1.0 için rapor edilen bu ataklar, 2002 yılında, Hawkes ve Rose’un “tahmin et ve belirle”, Coppersmith, Halevi and Jutla’nın “ayırt etme” ataklarıdır. SNOW’un tasarımcılarının 2002’de başka bir şifre, SOBER-t32, için yaptığı yaklaşım kullanılarak, bu tezde SNOW1.0’e yapılmış olan ayırt etme atağı yinelenmiştir. Fakat atak karmaşıklıklarını hesaplama yöntemleri farklı olduğundan, SNOW’un tasarımcılarının yöntemiyle bulunan değerler Coppersmith, Halevi ve Jutla’nın bulduklarından fazladır. Ayırt etme atağını mümkün kılan sonlu durum makinesindeki benzeşmeler ve bu benzeşmelerin Sonlu Durum Makinesi’ndeki işlemlerden nasıl etkilendiği araştırılmıştır. Yerleştirme kutuları Doğrusal Geri Beslemeli Kaydımalı Yazdırgaç’ın vi sebep olduğu doğrusallık ve benzeşmelerin ortadan kaldırılmasında önemli bir rol oynadığı için, SNOW’un yerleştirme kutularının özellikleri, Doğrusal Yaklaşım Tablosu, Fark Dağılımı Tablosu ve Oto-korelasyon Tablosu dağılımı ölçütlerine göre incelenmiştir. Ayrıca NIST istatiksel test ortamı kullanılarak her iki algoritma için de rassallık testleri yapılmış ve test sonuçları sunulmuştur. Anahtar Kelimeler: Akan Şifre, SNOW, Yerleştirme Kutusu, Ayırt Etme Atağı, Rassallık Testleri vii To My Family viii ACKNOWLEDGEMENTS I would like to express my sincere appreciation to my advisor, Assoc. Prof. Dr. Melek D. Yücel for her guidance, encouragement and support in every stage of this research. I am also grateful to my home-mates and colleagues for their encouragement and support. Finally, I would like to express my deep gratitude to all who have encouraged and helped me at the different stages of this work. And my parents and sister, I thank them for everything. ix TABLE OF CONTENTS ABSTRACT ............................................................................................................... iv ÖZ ............................................................................................................................. vi ACKNOWLEDGEMENTS.......................................................................................... ix TABLE OF CONTENTS .............................................................................................x LIST OF TABLES ..................................................................................................... xii LIST OF FIGURES...................................................................................................xiii CHAPTER 1 INTRODUCTION....................................................................................................1 2 STREAM CIPHERS ...............................................................................................5 2.1 Stream Ciphers.....................................................................................6 2.2 Linear Feedback Shift Registers...........................................................8 2.3 Introducing nonlinearity.......................................................................11 2.3.1 Boolean Functions ...................................................................12 2.3.2 S-Boxes....................................................................................16 2.3.3 Some Classic Stream Cipher Designs .....................................19 3 DESCRIPTION OF SNOW1.0 AND SNOW2.0....................................................21 3.1 Description of SNOW1.0.....................................................................21 3.2 Description of SNOW2.0.....................................................................25 3.3 Implementation Performances of SNOW............................................27 4 EXAMINATION OF SNOW1.0 AND SNOW2.0....................................................28 4.1 Examination of S-Boxes .....................................................................30 4.1.1 Linear Approximation Table .....................................................31 4.1.2 Difference Distribution and Auto-correlation Tables.................35 4.2 Analysis of the Finite State Machine...................................................37 4.2.1 Review of the Distinguishing Attack on SNOW1.0....................38 4.2.2 Approximating the FSM.............................................................40 4.2.3 Changing the S-Box ..................................................................41 4.2.4 Changing the “Integer Additions” with “Additions in F ” .........43 232 x 4.2.5 Eliminating the “Shift by 7” Operation .......................................44 4.2.6 Both Changing the S-Box and Other Operations ......................46 4.3 Results of Randomness Tests............................................................48 5 CONCLUSIONS ...................................................................................................52 REFERENCES.........................................................................................................54 APPENDICES APPENDIX A : S-Boxes of SNOW1.0 and Rijndael .............................................57 APPENDIX B : Description of Statistical Tests.....................................................59 xi LIST OF TABLES TABLES Table 2.1 : The Truth Table of the Boolean function f (x1 , x2 , x3 ) = x1 + x1 x2 + x2 x3 .................................................................................................................................13 Table 3.1 : Number of cycles needed for key setup and keystream generation on a Pentium 4 @1.8GHz ................................................................................................27 Table 4.1 : Complexities of attacks on SNOW1.0 and SNOW2.0 ............................29 Table 4.2 : Details for Figure 4.1 ..............................................................................32 Table 4.3 : Experimentally found correlation values in the FSM ..............................42 a) SNOW1.0 b) The s-box of SNOW1.0 is changed .................42 Table 4.4 : Experimentally found correlation values.................................................44 Table 4.5 : Results of the