International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Block Cipher Invariants as Eigenvectors of Correlation Matrices

Authors:
Tim Beyne
Download:
DOI: 10.1007/978-3-030-03326-2_1
Search ePrint
Search Google
Presentation: Slides
Conference: ASIACRYPT 2018
Award: Best Paper Award
Abstract: A new approach to invariant subspaces and nonlinear invariants is developed. This results in both theoretical insights and practical attacks on block ciphers. It is shown that, with minor modifications to some of the round constants, Midori-64 has a nonlinear invariant with $$2^{96}$$ corresponding weak keys. Furthermore, this invariant corresponds to a linear hull with maximal correlation. By combining the new invariant with integral cryptanalysis, a practical key-recovery attack on 10 rounds of unmodified Midori-64 is obtained. The attack works for $$2^{96}$$ weak keys and irrespective of the choice of round constants. The data complexity is $$1.25 \cdot 2^{21}$$ chosen plaintexts and the computational cost is dominated by $$2^{56}$$ block cipher calls. Finally, it is shown that similar techniques lead to a practical key-recovery attack on MANTIS-4. The full key is recovered using 640 chosen plaintexts and the attack requires about $$2^{56}$$ block cipher calls.
BibTeX
@inproceedings{asiacrypt-2018-29136,
  title={Block Cipher Invariants as Eigenvectors of Correlation Matrices},
  booktitle={Advances in Cryptology – ASIACRYPT 2018},
  series={Lecture Notes in Computer Science},
  publisher={Springer},
  volume={11272},
  pages={3-31},
  doi={10.1007/978-3-030-03326-2_1},
  author={Tim Beyne},
  year=2018
}