J4

• Original Articles • Previous Articles     Next Articles

Impossible differential attack on the 17-round block cipher SMS4

CHEN Jie;HU Yu-pu;ZHANG Yue-yu
  

  1. (Ministry of Education Key Lab. of Computer Network and Information Security, Xidian Univ., Xi′an 710071, China)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-06-20 Published:2008-05-30
  • Contact: CHEN Jie E-mail:jchen@mail.xidian.edu.cn

Abstract: The SMS4 is the first commercial block cipher published by our government in 2006. By analyzing the changes of the difference between input and output pairs in each round, this paper first presents an impossible differential property for the 14-round SMS4 if the difference of the input plaintext pair is (a, a, a, 0), it is impossible that the difference of 14-round output pair is (a, a, a, 0). Based on this property, a new method is proposed for cryptanalyzing the 17-round SMS4, which is to add two rounds and one round to each end of the impossible differential cryptanalysis for the 14-round SMS4. This attack on the reduced 17-round SMS4 requires about 2103 chosen plaintexts, performs 2124 17-round SMS4 encryptions, and demands 289 words of memory. Furthermore, the probability of its failure to recover the secret key is only 2-88.7.

Key words: block cipher, SMS4, impossible differential attack

CLC Number: 

  • TN918.1