Cryptology ePrint Archive: Report 2013/301

Impossible Differential-Linear Cryptanalysis of Reduced-Round CLEFIA-128

Zheng Yuan and Xian Li

Abstract: CLEFIA is a 128-bit block cipher proposed by Sony Corporation in 2007. Our paper introduces a new chosen text attack, the impossible differential-linear attack, on iterated cryptosystems. The attack is efficient for $16$-round CLEFIA with whitening keys. In the paper, we construct a $13$-round impossible differential-linear distinguisher. Based on the distinguisher, we present an effective attack on 16-round CLEFIA-$128$ with data complexity of $2^{122.73}$, recovering $96$-bit subkeys in total. The results of $15$-round CLEFIA-128 are given in Appendix C. Our attack can also be applied to CLEFIA-192 and CLEFIA-$256$.

Category / Keywords: CLEFIA, impossible differential-linear cryptanalysis, impossible differential cryptanalysis, linear approximation.

Date: received 20 May 2013, last revised 10 Feb 2014

Contact author: zyuan at tsinghua edu cn; sharonlee0915@163 com

Available format(s): PDF | BibTeX Citation

Note: We complement the third chapter, that is say, we introduced in detail our attack thoughts.

Version: 20140210:161507 (All versions of this report)

Discussion forum: Show discussion | Start new discussion


[ Cryptology ePrint archive ]