Font Size: a A A

Linear Cryptanalysis Of Multi2

Posted on:2015-02-14Degree:MasterType:Thesis
Country:ChinaCandidate:Y Q MaFull Text:PDF
GTID:2268330431456847Subject:Information security
Abstract/Summary:PDF Full Text Request
Developed by Hitachi, MULTI2(Multi-Media Encryption Algorithm2) is a block cipher used mainly to secure the multimedia content. It was registered in ISO/IEC9979in1994and was patented in US and Japan. MULTI2is a Feistel cipher with a64-bit block, a256-bit system key and a64-bit data key. According to the ISO standard, the number of rounds should be at least32, which is the same as that used in the ISDB standard. The key schedule of MULTI2extends the64-bit data key (as plaintext) to a256-bit encryption key using the256-bit system key. Then the encryption key is divided into832-bit round keys which are used in the first8rounds and repeated every8rounds. The encryption algorithm include4round functions π1经、 π2、π3、π4、which are used repeatedly in this order.This paper refers to two articles "Cryptanalysis of the ISDB Scrambling Algorithm (MULTI2)" and "Improved Linear Analysis on Block Cipher MULTI2" about the linear analysis on MULTI2. In this paper, we discuss the weak-key properties of function π2and function/π4using probabilistic methods. In the weak-key space of functiontπ2, denoted by K2k={k=(k31,k30,…,k0)|k30=k29=k28=k27=k26=k25=k24=0}, the correlation|Corπ2(α,β)|is relatvely high when the input mask is α=0x9c000001and the output mask is β=0x00000001. The experimental results show that the correlation is higher than2-1. At the same time, the experiments suggested a high probability for the correlation greater than2-1.5when the input masks are α=0x90000001,0x96000001,0x9a000001and the output mask is β=0x00000001.In the weak-key space of function π4,denoted by K4k={k=(k31,k30,…,k0)|k29=k28},the correlation is also relatively high|Corπ4(α,β)|≥21-when the input mask is α=0x40000001and the output mask is β=0x00000001.This paper also utilizes the Walsh transform.To generally analyze the linear properties of the function like π4,the linear analysis is combined with the generalized Walsh transform.We give the definition of the function like π4,which is y=fk(r),where x=r+k and y=(<<<m)+x+l.As a result,we get the quantitative relation between the round key and the correlation.Then the round key can be calculated directly from the value of correlation.In the end,the paper gives the possible modes of4-round linear path.Then using the high correlations obtained above,this paper shows a new4-round linear path with high correlation|Corπ1,π2,π3,π4(α|β,r|δ)|≥2-2,when the input mask is (α=0x90000000,β=0x9c000001) and the output mask is (γ=0x00000000,δ=0x40000001).
Keywords/Search Tags:MULTI2, block cipher, linear cryptanalysis, Walsh transforms, weak keys
PDF Full Text Request
Related items