The Square Attack of Reduced-Round Camellia

Xiaoli Yu, Hongru Wei · 2009

Duo etl. gave some equivalent structures of Camellia and some observations on Camellia, but they misunderstood the key scheduling algorithm of Camellia and had the wrong complexity for some case. In this paper, we first give some four round distinguishers, then present the square attack to 7-round Camellia and 9-round Camellia, furthermore modify some analysis complexities. 7-round Camellia-128 is breakable with the complexity of 225.6encryptions. 9-round Camellia-128 is breakable with the complexity of 2122encryptions. 7-round Camellia-256 is break-able with the complexity of 225.6encryptions. 9-round Camellia-256 is breakable with the complexity of 2122encryptions. 11-round Camellia-256 is breakable with the complexity of 2250encryptions.

Read the paper · More papers on PaperTik