Can GOST Be Made Secure Against Differential Cryptanalysis?
Nicolas T. Courtois, Theodosis Mourouzis, Michał Misztal, Jean-Jacques Quisquater, Guangyan Song · Cryptologia · 2015
GOST is a well-known Russian government standard block cipher which was submitted to ISO in 2010 to become an international standard. A number of advanced differential attacks on GOST have been proposed including the best known single-key attack on GOST to date in 2179 [14 Courtois, N. 2012. Security Evaluation of GOST 28147–89 In View of International Standardisation, Cryptologia, 36(1):2–13.[Taylor & Francis Online], [Web of Science ®] , [Google Scholar]]. This attack, however, was designed for the oldest known set of GOST S-boxes hoping that similar attacks should exist for other versions of GOST. This claim was bitterly disputed by Russian researchers as recently as July 2012, who stated that “S-boxes heavily affect security” and “with ‘good’ S-boxes the attack fails” [32 Rudskoy, V., and A. Dmukh. 2012. Algebraic and Differential Cryptanalysis of GOST: Fact or Fiction, In CTCrypt 2012, 2 July 2012, Nizhny Novgorod, Russia. An extended abstract is available at https://www.tc26.ru/invite/spisokdoc/CTCrypt_rudskoy.pdf. Slides are available at https://www.tc26.ru/documentary%20materials/CTCrypt%202012/slides/CTCrypt_rudskoy_slides_final.pdf. [Google Scholar]].Nothing can be more mistaken. In this article, the authors review 40 years of development of block ciphers in order to resist differential attacks. They study all ten known sets of GOST S-boxes. It appears that the choice of S-boxes has a limited effect on the actual security of GOST against advanced differential attacks. There is no evidence that the version of GOST submitted to ISO in 2011 is stronger than any previous version of GOST.