TY - GEN
T1 - Counting active S-boxes is not enough
AU - Dunkelman, Orr
AU - Kumar, Abhishek
AU - Lambooij, Eran
AU - Sanadhya, Somitra Kumar
N1 - Publisher Copyright: © Springer Nature Switzerland AG 2020.
PY - 2020
Y1 - 2020
N2 - Inspired by the works of Nyberg and Knudsen, the wide trail strategy suggests to ensure that the number of active S-boxes in a differential characteristic or a linear approximation is sufficiently high, thus, offering security against differential and linear attacks. Many cipher designers are relying on this strategy, and most new designs include analysis based on counting the number of active S-boxes. Unfortunately, this analysis is not always accurate and needs to be performed in a very delicate manner. To counter the common approach, we give an example of a 4-round Feistel construction with a very large number of active S-boxes that is expected to resist differential and linear cryptanalysis. However, we show that S-box counting arguments are insufficient in cases where one can find many differential characteristics with the same input and output difference. Namely, we show for a “provably” secure 128-bit block, 4-round Feistel with at least 36 active AES S-boxes, that one can construct differential characteristics with probability 2- 118 much higher than the bound of 2- 216. Even if we compare this 4-round Feistel construction to a random permutation we obtain a 10x factor in the probability of the characteristic.
AB - Inspired by the works of Nyberg and Knudsen, the wide trail strategy suggests to ensure that the number of active S-boxes in a differential characteristic or a linear approximation is sufficiently high, thus, offering security against differential and linear attacks. Many cipher designers are relying on this strategy, and most new designs include analysis based on counting the number of active S-boxes. Unfortunately, this analysis is not always accurate and needs to be performed in a very delicate manner. To counter the common approach, we give an example of a 4-round Feistel construction with a very large number of active S-boxes that is expected to resist differential and linear cryptanalysis. However, we show that S-box counting arguments are insufficient in cases where one can find many differential characteristics with the same input and output difference. Namely, we show for a “provably” secure 128-bit block, 4-round Feistel with at least 36 active AES S-boxes, that one can construct differential characteristics with probability 2- 118 much higher than the bound of 2- 216. Even if we compare this 4-round Feistel construction to a random permutation we obtain a 10x factor in the probability of the characteristic.
KW - Differential cryptanalysis
KW - Feistel ciphers
KW - Wide trail
UR - https://www.scopus.com/pages/publications/85098288942
U2 - 10.1007/978-3-030-65277-7_15
DO - 10.1007/978-3-030-65277-7_15
M3 - Conference contribution
SN - 9783030652760
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 332
EP - 344
BT - Progress in Cryptology – INDOCRYPT 2020 - 21st International Conference on Cryptology in India 2020, Proceedings
A2 - Bhargavan, Karthikeyan
A2 - Oswald, Elisabeth
A2 - Prabhakaran, Manoj
PB - Springer Science and Business Media Deutschland GmbH
T2 - 21st International Conference on Cryptology in India, INDOCRYPT 2020
Y2 - 13 December 2020 through 16 December 2020
ER -