Presentation 2001/3/16
A Study on Strength of RC6 against Higher Order Differential Attack
Yasuhiro OHGAKI, Hiroshi TANAKA, Toshinobu KANEKO,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) RC6 proposed by Rivest et al, is a block cipher and one ofa 5-finalists of AES. User can choose word length w, number of rounds r and key length k, AES version has w=32[bit] and r=20. We discuss the security of Round function from the viewpoint of improved Higher Order Differential Attack. The attack is a kind of chosen plaintext attack, and choice of effective set of plaintexts is important. We found two kinds of effective set of plaintexts based on concept of "balance". One is derived from "balance" in the output of data-dependent rotation, and the other is from "balance" in the output of the integer addition. As a result, we can attack 4 iterative round function using 2nd order differentials. We made a computer simulation, and succeeded in determining the Round Key used in 4th Round in about an hour. When 2-rounds elimination technique is used, the attack needs 128 chosen plaintexts, and 2^<98> times the computation of the round function.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) Block Cipher / RC6 / Chosen Plain Text Attack / Higher Order Differential Attack
Paper # IT2000-80,ISEC2000-134,SST2000-164,ITS2000-89
Date of Issue

Conference Information
Committee IT
Conference Date 2001/3/16(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Information Theory (IT)
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) A Study on Strength of RC6 against Higher Order Differential Attack
Sub Title (in English)
Keyword(1) Block Cipher
Keyword(2) RC6
Keyword(3) Chosen Plain Text Attack
Keyword(4) Higher Order Differential Attack
1st Author's Name Yasuhiro OHGAKI
1st Author's Affiliation Department of Electrical Engineering, Science University of TOKYO()
2nd Author's Name Hiroshi TANAKA
2nd Author's Affiliation Department of Electrical Engineering, Science University of TOKYO
3rd Author's Name Toshinobu KANEKO
3rd Author's Affiliation Department of Electrical Engineering, Science University of TOKYO
Date 2001/3/16
Paper # IT2000-80,ISEC2000-134,SST2000-164,ITS2000-89
Volume (vol) vol.100
Number (no) 690
Page pp.pp.-
#Pages 8
Date of Issue