Pitfalls in Designing Substitution Boxes (Extended Abstract)

Jennifer Seberry, Xian-Mo Zhang, Yuliang Zheng · 1994

) Jennifer Seberry, Xian-Mo Zhang and Yuliang Zheng Department of Computer Science University of Wollongong, Wollongong, NSW 2522, Australia fjennie, xianmo, [email protected] Abstract. Two significant recent advances in cryptanalysis, namely the differential attack put forward by Biham and Shamir [3] and the linear attack by Matsui [7, 8], have had devastating impact on data encryption algorithms. An eminent problem that researchers are facing is to design S-boxes or substitution boxes so that an encryption algorithm that employs the S-boxes is immune to the attacks. In this paper we present evidence indicating that there are many pitfalls on the road to achieve the goal. In particular, we show that certain types of S-boxes which are seemly very appealing do not exist. We also show that, contrary to previous perception, techniques such as chopping or repeating permutations do not yield cryptographically strong S-boxes. In addition, we reveal an important combinatorial structure...

Read the paper · More papers on PaperTik