中文

从可证明安全性视角理解Feistel密码的相关密钥安全性

密码学与安全 2019-03-06 v3

摘要

我们针对实用Feistel密码模型开启了可证明的相关密钥安全性研究。具体而言,我们考虑带有四个白化密钥wi(k)w_i(k)i=0,1,2,3i=0,1,2,3)且轮函数形式为f(γi(k)X)f(\gamma_i(k)\oplus X)的Feistel网络,其中kk为主密钥,wiw_iγi\gamma_i为高效变换,ff为允许敌手查询的公开理想函数或置换。我们探究了在多达2n/22^{n/2}次敌手查询下,足以抵御异或诱导相关密钥攻击的密钥调度条件。当密钥调度为非线性时,我们证明了4轮的安全性。当仅使用仿射密钥调度时,我们证明了6轮的安全性。这些结果也意味着在随机预言机模型下安全的可调Feistel密码。通过打乱密钥调度,我们的模型统一了类DES结构(在密码分析界称为Feistel-2方案,亦即Lampe与Seurin于FSE 2014提出的密钥交替Feistel)与类Lucifer模型(此前由Guo与Lin于TCC 2015分析)。这使我们能够推导出关于这两种(更常见的)模型的具体结论,并有助于理解其差异——进而进一步理解Feistel密码的相关密钥安全性。

关键词

引用

@article{arxiv.1810.07428,
  title  = {Understanding the Related-Key Security of Feistel Ciphers from a Provable Perspective},
  author = {Chun Guo},
  journal= {arXiv preprint arXiv:1810.07428},
  year   = {2019}
}

备注

The technical part is the same as the submission (only modify to fit into the double column). In "Related Work" comparison with [72] is added: in short, these two works focus on very different goals, and their general results aren't comparable