2010IACR Cryptology ePrint ArchiveRequires access

Differential Cryptanalysis of SMS4 Block Cipher.

Bozhan Su, Wenling Wu, Wentao Zhang

Open publisher page 8 citations

Abstract

SMS4 is a 128-bit block cipher used in the WAPI standard for wireless networks in China. In this paper, we analyze the security of SMS4 block cipher against differential cryptanalysis. Firstly, we prove three theorems and one corollary that reflect relationships of 5and 6round SMS4. Nextly, by these relationships, we clarify the minimum number of differentially active S-boxes in 6-, 7and 12-round SMS4 respectively. Finally, based on the above results, we present a family of about 2 differential characteristics for 19-round SMS4, which leads to an attack on 23-round SMS4 with 2 chosen plaintexts and 2 encryptions. Our attack is the best known attack on SMS4 so far.

About this research paper

What this paper is about

SMS4 is a 128-bit block cipher used in the WAPI standard for wireless networks in China. In this paper, we analyze the security of SMS4 block cipher against differential cryptanalysis. Firstly, we prove three theorems and one corollary that reflect relationships of 5and 6round SMS4. Nextly, by these relationships, we clarify the minimum number of differentially active S-boxes in 6-, 7and 12-round SMS4 respectively. Finally, based on the above results, we present a family of about 2 differential characteristics for 19-round SMS4, which leads to an attack on 23-round SMS4 with 2 chosen plaintexts and 2 encryptions. Our attack is the best known attack on SMS4 so far.

Why it matters

OpenAlex reports 8 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

SMS4 is a 128-bit block cipher used in the WAPI standard for wireless networks in China. In this paper, we analyze the security of SMS4 block cipher against differential cryptanalysis. Firstly, we prove three theorems and one corollary that reflect relationships of 5and 6round SMS4. Nextly, by these relationships, we clarify the minimum number of differentially active S-boxes in 6-, 7and 12-round SMS4 respectively. Finally, based on the above results, we present a family of about 2 differential characteristics for 19-round SMS4, which leads to an attack on 23-round SMS4 with 2 chosen plaintexts and 2 encryptions. Our attack is the best known attack on SMS4 so far.

Key concepts: Impossible differential cryptanalysis, Boomerang attack, Block cipher, Differential cryptanalysis, Higher-order differential cryptanalysis, Transposition cipher, Two-square cipher, Linear cryptanalysis

Related papers

Back to paper searchBrowse research topicsOriginal source
Differential Cryptanalysis of SMS4 Block Cipher. — Research Paper | ScholarLens