arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

AES128的黑盒密码分析

Black Box Cryptanalysis of AES128

Virendra Sule, Kunal Telangi

arXiv 2608.22904首次发表:更新:

AI 中文总结

本文提出一种基于黑盒局部逆变换的AES128密钥恢复方法,可在已知明文攻击下实用可行地恢复80位密钥,通过外推与并行搜索有望破解全128位密钥,该方法也适用于其他类似强度密码的分析。

AI 中文摘要

本文呈现了使用正向加密的黑盒计算进行局部逆变换的AES密码分析计算结果,并利用这些结果开发了一种在已知明文攻击(KPA)下针对全尺寸AES128的实用可行密钥恢复方法。研究表明,在随机KPA场景中,当剩余48位密钥已知时,通过顺序计算可在实用可行的时间和内存内完整恢复多达80位未知密钥位。将64位、72位和80位未知密钥情况下的密钥恢复结果外推,以预测全128位未知密钥情况下局部逆变换方法生成的迭代序列周期,并提出一种策略,通过对序列周期进行暴力并行搜索(搜索空间由10个自由位定义)来搜索实际周期。随后证明,通过正向加密映射的快速幂运算可在多项式时间内验证实际密钥。因此,该策略表明在KPA下AES128的密钥恢复问题有很高的成功概率,且所需时间实用可行。使用黑盒计算的密码分析局部逆变换方法是一种通用方法,适用于大量密钥恢复和映射逆问题。因此,本文呈现的结果代表了对其他可视为与AES128加密强度相当的密码的密码分析估计。

英文摘要

This paper presents computational results of cryptanalysis of AES using the Local Inversion by Black Box computations of the forward encryption and utilizes these results to develop a practically feasible approach for the key recovery of the full scale AES128 under Known Plaintext Attack (KPA). It is shown that complete recovery of unknown key bits is possible upto $80$ bits in a practically feasible time and memory in random KPA situation by sequential computation when remaining $48$ bits are known. The results of key recovery in $64$, $72$ and $80$ bit unknown cases are extrapolated to predict the period of the iterative sequence generated in the local inversion approach for the full $128$ bit unknown key case and a strategy is proposed to search the actual period by brute force parallel search of the sequence period with $10$ free bits defining the search space. Then it is shown that the actual key can be verified in polynomial time by fast powering of the forward encryption map. Hence this strategy shows that the key recovery problem for AES128 under KPA has a chance of success in practically feasible time for a majority of the plaintexts. Local inversion approach to cryptanalysis using black box computations is a universal method applicable to a vast variety of key recovery and map inversion problems. Hence the results presented in this paper are representative of estimates of cryptanalysis of other ciphers which can be considered almost as strong as AES128 as encryption functions.

Comments14 pages, two figures, 3 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑