This paper investigates the relation between the choice of S-boxes and Square attack.A variant Camellia,which uses only a single S-box instead of four,is proposed.The security of the variant Camellia against Square at...This paper investigates the relation between the choice of S-boxes and Square attack.A variant Camellia,which uses only a single S-box instead of four,is proposed.The security of the variant Camellia against Square attack is studied in detail.Result shows that it needs only 28 chosen plaintexts to recover a byte of the 6th round-key of variant Camellias,while the original Camellia needs either 28 chosen plaintexts to recover a byte of the 6th round-key and a byte of some constant or 216 chosen plaintexts to recover a byte of the 6th roundkey.Furthermore,Square attacks on other round-reduced variant Camellia are proposed,and the time complexity of 11-round attack is reduced from 2^(250)to 2^(225.5).The weaker variant Camellia indicates that the choice of S-box and the order of different S-boxes have influence on Square attack.展开更多
基金This work was supported by the Planned Science and Technology Project of Hunan Province of China(No.2010FJ4079)A Project Supported by Scientific Research Fund of Hunan Provincial Education Department.
文摘This paper investigates the relation between the choice of S-boxes and Square attack.A variant Camellia,which uses only a single S-box instead of four,is proposed.The security of the variant Camellia against Square attack is studied in detail.Result shows that it needs only 28 chosen plaintexts to recover a byte of the 6th round-key of variant Camellias,while the original Camellia needs either 28 chosen plaintexts to recover a byte of the 6th round-key and a byte of some constant or 216 chosen plaintexts to recover a byte of the 6th roundkey.Furthermore,Square attacks on other round-reduced variant Camellia are proposed,and the time complexity of 11-round attack is reduced from 2^(250)to 2^(225.5).The weaker variant Camellia indicates that the choice of S-box and the order of different S-boxes have influence on Square attack.