An improved impossible differential attack on MISTY1

Orr Dunkelman, Nathan Keller

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

40 Scopus citations

Abstract

MISTY1 is a Feistel block cipher that received a great deal of cryptographic attention. Its recursive structure, as well as the added FL layers, have been successful in thwarting various cryptanalytic techniques. The best known attacks on reduced variants of the cipher are on either a 4-round variant with the FL functions, or a 6-round variant without the FL functions (out of the 8 rounds of the cipher). In this paper we combine the generic impossible differential attack against 5-round Feistel ciphers with the dedicated Slicing attack to mount an attack on 5-round MISTY1 with all the FL functions with time complexity of 246.45 simple operations. We then extend the attack to 6-round MISTY1 with the FL functions present, leading to the best known cryptanalytic result on the cipher. We also present an attack on 7-round MISTY1 without the FL layers.

Original languageEnglish
Title of host publicationAdvances in Cryptology - ASIACRYPT 2008 - 14th International Conference on the Theory and Application of Cryptology and Information Security, Proceedings
Pages441-454
Number of pages14
DOIs
StatePublished - 2008
Externally publishedYes
Event14th International Conference on the Theory and Application of Cryptology and Information Security, ASIACRYPT 2008 - Melbourne, VIC, Australia
Duration: 7 Dec 200811 Dec 2008

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5350 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference14th International Conference on the Theory and Application of Cryptology and Information Security, ASIACRYPT 2008
Country/TerritoryAustralia
CityMelbourne, VIC
Period7/12/0811/12/08

Fingerprint

Dive into the research topics of 'An improved impossible differential attack on MISTY1'. Together they form a unique fingerprint.

Cite this