摘要
This paper investigates the relation between the choice of S-boxes and Square attack.A variant Camellia,which uses only a single S-box instead of four,is proposed.The security of the variant Camellia against Square attack is studied in detail.Result shows that it needs only 28 chosen plaintexts to recover a byte of the 6th round-key of variant Camellias,while the original Camellia needs either 28 chosen plaintexts to recover a byte of the 6th round-key and a byte of some constant or 216 chosen plaintexts to recover a byte of the 6th roundkey.Furthermore,Square attacks on other round-reduced variant Camellia are proposed,and the time complexity of 11-round attack is reduced from 2^(250)to 2^(225.5).The weaker variant Camellia indicates that the choice of S-box and the order of different S-boxes have influence on Square attack.
基金
This work was supported by the Planned Science and Technology Project of Hunan Province of China(No.2010FJ4079)
A Project Supported by Scientific Research Fund of Hunan Provincial Education Department.