A detailed analysis of SAFER K

Authors
Citation
Lr. Knudsen, A detailed analysis of SAFER K, J CRYPTOL, 13(4), 2000, pp. 417-436
Citations number
16
Categorie Soggetti
Computer Science & Engineering
Journal title
JOURNAL OF CRYPTOLOGY
ISSN journal
09332790 → ACNP
Volume
13
Issue
4
Year of publication
2000
Pages
417 - 436
Database
ISI
SICI code
0933-2790(200023)13:4<417:ADAOSK>2.0.ZU;2-Q
Abstract
In this paper we analyze the block cipher SAFER K. First, we show a weaknes s in the key schedule, that has the effect that for almost every key there exists on the average three and a half other keys such that the encryptions of plaintexts different in one of eight bytes yield ciphertexts also diffe rent in only one byte. Moreover, the differences in the keys, plaintexts, a nd ciphertexts are in the same byte. This enables us to do a related-key ch osen plaintext attack on SAFER K, which finds the secret key. Also, the sec urity of SAFER K, when used in standard hashing modes, is greatly reduced, which is illustrated. Second, we propose a new key schedule for SAFER K avo iding these problems. Third, we do differential cryptanalysis of SAFER K. W e consider truncated differentials and apply them in an attack on five-roun d SAFER K, which finds the secret key much faster than by an exhaustive sea rch.