Study of the invariant coset attack on PRINTcipher: more weak keys with practical key recovery

Stanislav Bulygin, Michael Walter · IACR Cryptology ePrint Archive · 2012

In this paper we investigate the invariant property of PRINTcipher first discovered by Leander et al. in their CRYPTO 2011 paper. We provide a thorough study of the question, showing that there exist 64 classes of weak keys for PRINTcipher--48 and many more for PRINTcipher--96. We show that for many classes of weak keys the key recovery can be done in a matter of minutes in the chosen plaintext scenario. In fact, at least $2^{48}$ weak keys can be recovered in less than 20 minutes per key on a single PC using only a few chosen plaintexts. We provide detailed treatment of the methods and put them in a more general context that opens new interesting directions of research for PRESENT-like ciphers.

Read the paper · More papers on PaperTik