Courtois, NT;
Oprisanu, M-B;
Schmeh, K;
(2019)
Linear cryptanalysis and block cipher design in East Germany in the 1970s.
Cryptologia
, 43
(1)
pp. 2-22.
10.1080/01611194.2018.1483981.
Preview |
Text
T310_linear_ucry.pdf - Accepted Version Download (1MB) | Preview |
Abstract
Linear cryptanalysis (LC) is an important codebreaking method that became popular in the 1990s and has roots in the earlier research of Shamir in the 1980s. In this article we show evidence that linear cryptanalysis is even older. According to documents from the former East Germany cipher authority ZCO, the systematic study of linear characteristics for nonlinear Boolean functions was routinely performed in the 1970s. At the same time East German cryptologists produced an excessively complex set of requirements known as KT1, which requirements were in particular satisfied by known historical used in the 1980s. An interesting line of inquiry, then, is to see if KT1 keys offer some level of protection against linear cryptanalysis. In this article we demonstrate that, strangely, this is not really the case. This is demonstrated by constructing specific counterexamples of pathologically weak keys that satisfy all the requirements of KT1. However, because we use T-310 in a stream cipher mode that uses only a tiny part of the internal state for actual encryption, it remains unclear whether this type of weak key could lead to key recovery attacks on T-310.
Type: | Article |
---|---|
Title: | Linear cryptanalysis and block cipher design in East Germany in the 1970s |
Open access status: | An open access version is available from UCL Discovery |
DOI: | 10.1080/01611194.2018.1483981 |
Publisher version: | https://doi.org/10.1080/01611194.2018.1483981 |
Language: | English |
Additional information: | This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions. |
Keywords: | ANF, backdoors, block cipher, Boolean functions, Cold War, linear cryptanalysis, SKS V/1, T-310, weak keys |
UCL classification: | UCL UCL > Provost and Vice Provost Offices > UCL BEAMS UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science |
URI: | https://discovery.ucl.ac.uk/id/eprint/10133807 |
Archive Staff Only
View Item |