Cryptanalysis of Two GOST Variants with 128-Bit Keys
Nicolas T. Courtois · Cryptologia · 2014
GOST is a well-known Russian encryption standard. Until 2010, no researcher found a single-key attack on GOST. In 2010, GOST was submitted to ISO 18033 to become a worldwide industrial encryption standard. Since 2011, many attacks on GOST faster than brute force have been found [Citation3, Citation4, Citation5, Citation10, Citation12]. By default, GOST has 256-bit keys. However, in many applications 128-bit keys are required. The authors should note that GOST is an exceptionally economical cipher in implementation: Even as a 128-bit cipher, GOST requires about four times less gates to implement than AES-128 (see [Citation16]). There are two very natural 128-bit variants of GOST: Either the same 128-bit key is repeated, or it is repeated with inversion of the 32-bit words. Both variants are natural simplified variants fully compliant with the standard which have already been considered as potentially interesting targets for advanced slide attacks [Citation2]. In this article, the authors show that both these variants are insecure. All of their attacks are nearly practical.