New Correlations of RC4 PRGA Using Nonzero-Bit Differences
抄録
RC4 is the stream cipher proposed by Rivest in 1987, which is widely used in a number of commercial products because of its simplicity and substantial security. RC4 exploits shuffle-exchange paradigm, which uses a permutation S. Many attacks have been reported so far. No study, however, has focused on correlations in the Pseudo-Random Generation (PRGA) between two permutations S and S′ with some differences, nevertheless such correlations are related to an inherent weakness of shuffle-exchange-type PRGA. In this paper, we investigate the correlations between S and S′ with some differences in the initial round. We show that correlations between S and S′ remain before "i" is in the position where the nonzero-bit difference exists in the initial round, and that the correlations remain with non negligible probability even after "i" passed by the position. This means that the same correlations between S and S′ will be observed after the 255-th round. This reveals an inherent weakness of shuffle-exchange-type PRGA.Proceedings of the 14th Australasian Conference, ACISP 2009 Brisbane, Australia, July 1-3, 2009.
収録刊行物
-
- Lecture Notes in Computer Science
-
Lecture Notes in Computer Science (5594), 134-152, 2009
Springer
- Tweet
キーワード
詳細情報 詳細情報について
-
- CRID
- 1574231877345966208
-
- NII論文ID
- 120002260315
-
- ISSN
- 03029743
-
- Web Site
- http://hdl.handle.net/10119/9068
-
- 本文言語コード
- en
-
- データソース種別
-
- CiNii Articles