Differential ananlysis of 3 round Kuznyechik
Evgeniya Ishchukova, Ekaterina Tolomanenko, Liudmila K. Babenko · 2017
In January 2016, a new block encryption standard came into force in the Russian Federation - GOST R 34.12-2015. It includes two algorithms of encryption. The first cipher was previously known under the name GOST28147-89 (or simply GOST). The second algorithm was called Kuznyechik. Kuznyechik is a new symmetric encryption algorithm, based on the SP-network. Up to now there are no publications about the differential properties of the algorithm Kuznyechik. We are the first to examine the properties of main operations and suggest a scheme of 3 rounds differential analysis of cipher Kuznyechik. We examined the differential properties of the non-linear transformation S and the linear transformation L and found out that it's possible a situation when, 1 non-zero byte difference, being a result of the transformation L, is expanded into 16 non-zero bytes, then it passes through the S-boxes, and then collapses again into 1 nonzero byte. The developed scheme allows to affect the active S-boxes a minimum number of times. As a result, for the suggested scheme the possibility of finding the correct pairs of texts is equal to 2-108. We also developed the algorithm of finding a secret key, the complexity of which is equal to 6*2−120. In this way, the total complexity of the analysis, including searching for the correct pairs of texts and bits of the secret encryption key is equal to 2108 + 6*2120 encryptions.