Have a personal or library account? Click to login
ROTATIONAL CRYPTANALYSIS OF GOST WITH IDENTICAL S-BOXES Cover

ROTATIONAL CRYPTANALYSIS OF GOST WITH IDENTICAL S-BOXES

By: Pavol Zajac and  Michal Ondroš  
Open Access
|Feb 2014

Abstract

Rotational cryptanalysis was introduced by Khovratovich and Nikoli ´c as a tool to analyse ARX-type cipher designs. GOST 28147-89 is a former Soviet Union cipher standard based on a Feistel construction with 32 rounds. Each round function adds the round key modulo 232, transforms the result with 4-to-4 bit S-boxes, and rotates the output. We apply the rotational cryptanalysis to a version of GOST using eight identical S-boxes, such as GOST-PS. We show the existence of (practical) rotational distinguisher in related key model for full GOST. Furthermore, there is a set of weak keys (rotationally symmetric keys) that enables rotational attacks in single-key model as well. Finally, we show a simple attack on the last round that uses the rotational distinguisher to reduce the complexity of the full GOST to 208 bits.

DOI: https://doi.org/10.2478/tmmp-2013-0032 | Journal eISSN: 1338-9750 | Journal ISSN: 12103195
Language: English
Page range: 1 - 19
Published on: Feb 18, 2014
Published by: Slovak Academy of Sciences, Mathematical Institute
In partnership with: Paradigm Publishing Services
Publication frequency: 3 issues per year

© 2014 Pavol Zajac, Michal Ondroš, published by Slovak Academy of Sciences, Mathematical Institute
This work is licensed under the Creative Commons License.