Institutional Repository
| 流密码算法Grain的立方攻击 | |
| Alternative Title | cube attack on grain |
| 宋海欣; 范修斌; 武传坤; 冯登国 | |
| 2012 | |
| Source | Journal of Software
![]() |
| ISSN | 1000-9825 |
| Volume | 23Issue:1Pages:171-176 |
| English Abstract | Dinur和Shamir在2009年欧洲密码年会上提出了立方攻击的密码分析方法.Grain算法是欧洲序列密码工程eSTREAM最终入选的3个面向 硬件实现的流密码算法之一,该算法密钥长度为80比特,初始向量(IV)长度为64比特,算法分为初始化过程和密钥流产生过程,初始化过程空跑160拍. 利用立方攻击方法对Grain算法进行了分析,在选择IV攻击条件下,若算法初始化过程空跑70拍,我们可恢复15比特密钥,并找到了关于另外23比特密 钥的4个线性表达式;若算法初始化过程空跑75拍,我们可恢复1比特密钥. |
| Abstract | At EUROCRYPT 2009, Dinur and Shamir proposed a new type of algebraic attacks named cube attack. Grain is one of the 3 final hardware-oriented stream ciphers in the eSTREAM portfolio, which takes as input an 80-bit secret key and a 64-bit initial vector, and produces its keystream after 160 rounds of initialization. Applying cube attack on Grain with 70 initialization rounds, we can recover 15-bit secret key and find 4 linear equations on another 23 bits of the secret key. Moreover, applying cube attack on Grain with 75 initialization rounds, we can recover 1-bit secret key. |
| Keyword | Grain Estream Project Stream Cipher Grain Cube Attack Key Recovery |
| Department | 宋海欣, 中国科学院软件研究所, 信息安全国家重点实验室, 北京 100190, 中国. 范修斌, 中国科学院软件研究所, 信息安全国家重点实验室, 北京 100190, 中国. 武传坤, 中国科学院软件研究所, 信息安全国家重点实验室, 北京 100190, 中国. 冯登国, 中国科学院软件研究所, 信息安全国家重点实验室, 北京 100190, 中国. |
| Subject | Computer Science |
| Language | 中文 |
| Content Type | 期刊论文 |
| URI | http://ir.iscas.ac.cn/handle/311060/14645 |
| Collection | 信息安全国家重点实验室 |
| Recommended Citation GB/T 7714 | 宋海欣,范修斌,武传坤,等. 流密码算法Grain的立方攻击[J]. Journal of Software,2012,23(1):171-176. |
| APA | 宋海欣,范修斌,武传坤,&冯登国.(2012).流密码算法Grain的立方攻击.Journal of Software,23(1),171-176. |
| MLA | 宋海欣,et al."流密码算法Grain的立方攻击".Journal of Software 23.1(2012):171-176. |
| Files in This Item: | ||||||
| File Name/Size | DocType | Version | Access | License | ||
| 流密码算法Grain的立方攻击.pdf(479KB) | 开放获取 | License | Application Full Text | |||
Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.
Edit Comment