The Square Attack of Reduced-Round Camellia
Duo etl. gave some equivalent structures of Camellia and some observations on Camellia, but they misunderstood the key scheduling algorithm of Camellia and had the wrong complexity for some case. In this paper, we first give some four round distinguishers, then present the square attack to 7-round C...
Gespeichert in:
Hauptverfasser: | , |
---|---|
Format: | Tagungsbericht |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | Duo etl. gave some equivalent structures of Camellia and some observations on Camellia, but they misunderstood the key scheduling algorithm of Camellia and had the wrong complexity for some case. In this paper, we first give some four round distinguishers, then present the square attack to 7-round Camellia and 9-round Camellia, furthermore modify some analysis complexities. 7-round Camellia-128 is breakable with the complexity of 2 25.6 encryptions. 9-round Camellia-128 is breakable with the complexity of 2 122 encryptions. 7-round Camellia-256 is break-able with the complexity of 2 25.6 encryptions. 9-round Camellia-256 is breakable with the complexity of 2 122 encryptions. 11-round Camellia-256 is breakable with the complexity of 2 250 encryptions. |
---|---|
DOI: | 10.1109/NSWCTC.2009.259 |