New Correlations of RC4 PRGA Using Nonzero-Bit Differences

抄録

RC4 is the stream cipher proposed by Rivest in 1987, which is widely used in a number of commercial products because of its simplicity and substantial security. RC4 exploits shuffle-exchange paradigm, which uses a permutation S. Many attacks have been reported so far. No study, however, has focused on correlations in the Pseudo-Random Generation (PRGA) between two permutations S and S′ with some differences, nevertheless such correlations are related to an inherent weakness of shuffle-exchange-type PRGA. In this paper, we investigate the correlations between S and S′ with some differences in the initial round. We show that correlations between S and S′ remain before "i" is in the position where the nonzero-bit difference exists in the initial round, and that the correlations remain with non negligible probability even after "i" passed by the position. This means that the same correlations between S and S′ will be observed after the 255-th round. This reveals an inherent weakness of shuffle-exchange-type PRGA.Proceedings of the 14th Australasian Conference, ACISP 2009 Brisbane, Australia, July 1-3, 2009.

収録刊行物

キーワード

詳細情報 詳細情報について

  • CRID
    1574231877345966208
  • NII論文ID
    120002260315
  • ISSN
    03029743
  • Web Site
    http://hdl.handle.net/10119/9068
  • 本文言語コード
    en
  • データソース種別
    • CiNii Articles

問題の指摘

ページトップへ