Impossible Differential Cryptanalysis of Reduced-Round LBlock-s

Ping JIA,Hong XU,Xue-jia LAI
DOI: https://doi.org/10.3969/j.issn.0372-2112
2017-01-01
Abstract:LBlock-s is the kernel block cipher of the authentication encryption algorithm LAC submitted to CAESAR competition.The general structure of LBlock-s is almost the same as that of LBlock,but LBlock-s adopts an improved key schedule algorithm with better diffusion property.Using the shifting relation of subkeys derived by the key schedule algorithm,an impossible differential cryptanalysis on 21-round LBlock-s was presented based on a 14-round impossible differential.The time and data complexities are 2.67.61 21-round encryptions and 2.63 chosen plaintexts respectively,and the number of subkey bits needed to be guessed is 72.Using partial-matching method,an impossible differential cryptanalysis on LBlock-s up to 23-round was also presented with time complexity less than exhaustion of all key bits.This work is useful for the security analysis of LAC algorithm.
What problem does this paper attempt to address?