In this paper, we present improved higher-order differential attacks on reduced-round MISTY1. Our attack on the variant considered by Tsunoo et al. requires roughly the same amount of data and only $2^{100.4}$ time (i.e., is $2^{16}$ times faster). Furthermore, we present the first attack on a MISTY1 variant with 7 rounds and all 5 $FL$ layers, requiring $2^{51.4}$ data and $2^{121}$ time. To achieve our results, we use a new higher-order differential characteristic for 4-round MISTY1, as well as enhanced key recovery algorithms based on the {\it partial sums} technique.
Category / Keywords: block cipher, MISTY1, higher-order differential attack, partial sums, integral attack, KASUMI Original Publication (with minor differences): IACR-FSE-2015 Date: received 22 Apr 2015 Contact author: abo1000 at gmail com Available format(s): PDF | BibTeX Citation Version: 20150423:131221 (All versions of this report) Short URL: ia.cr/2015/367 Discussion forum: Show discussion | Start new discussion