Flaws in differential cryptanalysis of Skipjack.

Louis Granboulan · 2001

Abstract. This paper is motivated by some results presented by Knudsen, Robshaw and Wagner at Crypto’99 [3], that described many attacks of reduced versions of Skipjack, some of them being erroneous. Differential cryptanalysis is based on distinguishers, any attack should prove that the events that triggers the analysis has not the same probability for the cipher than for a random function. In particular, the composition of differential for successive parts of a cipher should be done very carefully to lead to an attack. This revised version of the paper includes the exact computations of some probabilities and repairs the attack of the first half of Skipjack. 1 What Is Differential Cryptanalysis? Chosen plaintext attacks. If we have a “black box ” containing a symmetric block cipher, we are able to encrypt anything we want. The goal of the attack is to decrypt some given ciphertext, or even better to retrieve the key. Apartial success is obtained if we have a distinguisher, i.e. a technique that gives some information about what is in the box (e.g. the algorithm used). Looking at differences. In order to check the security of a block cipher under chosen plaintext attacks, we can make statistical tests on the output when the input is cleverly chosen. The differential cryptanalysis [2] looks at the difference in the output of the cipher when a pair of input texts with some particular difference (XOR) is enciphered. If the pair of input texts is randomly chosen with their difference following some special distribution of probability, the difference of the outputs may give some information about what is inside. Building a distinguisher using a differential. More precisely, if we know that, for some keys the input of two different plaintexts with a difference in the subset ∆ gives two ciphertexts with a difference in the subset ∆ ∗ with non trivial probability p (this is called a differential of probability p, the common notation is ∆ →p ∆ ∗), then we are able to distinguish two black boxes, one with

Read the paper · More papers on PaperTik