Skip to main content
QUICK REVIEW

[論文レビュー] A Novel Method to Generate Key-Dependent S-Boxes with Identical Algebraic Properties

Ahmad Y. Al‐Dweik, Iqtadar Hussain|arXiv (Cornell University)|Aug 24, 2019
Coding theory and cryptography参考文献 27被引用数 8
ひとこと要約

本稿では、SₙおよびS₂ⁿの対称群作用を用いてSボックスの行と列を置換することにより、同一の代数的性質(全単射、非線形性、厳密なアバランチ基準(SAC)、ビット独立性基準(BIC))を保持する、鍵依存の動的Sボックスを生成する新しいアルゴリズムを提案する。この手法により、生成されたすべてのクローンSボックスは元のSボックスと同一の暗号的強度を維持し、パフォーマンス指標を損なわずに安全で動的なSボックス生成が可能になる。

ABSTRACT

The s-box plays the vital role of creating confusion between the ciphertext and secret key in any cryptosystem, and is the only nonlinear component in many block ciphers. Dynamic s-boxes, as compared to static, improve entropy of the system, hence leading to better resistance against linear and differential attacks. It was shown in [2] that while incorporating dynamic s-boxes in cryptosystems is sufficiently secure, they do not keep non-linearity invariant. This work provides an algorithmic scheme to generate key-dependent dynamic $n imes n$ clone s-boxes having the same algebraic properties namely bijection, nonlinearity, the strict avalanche criterion (SAC), the output bits independence criterion (BIC) as of the initial seed s-box. The method is based on group action of symmetric group $S_n$ and a subgroup $S_{2^n}$ respectively on columns and rows of Boolean functions ($GF(2^n) o GF(2)$) of s-box. Invariance of the bijection, nonlinearity, SAC, and BIC for the generated clone copies is proved. As illustration, examples are provided for $n=8$ and $n=4$ along with comparison of the algebraic properties of the clone and initial seed s-box. The proposed method is an extension of [3,4,5,6] which involved group action of $S_8$ only on columns of Boolean functions ($GF(2^8) o GF(2)$ ) of s-box. For $n=4$, we have used an initial $4 imes 4$ s-box constructed by Carlisle Adams and Stafford Tavares [7] to generated $(4!)^2$ clone copies. For $n=8$, it can be seen [3,4,5,6] that the number of clone copies that can be constructed by permuting the columns is $8!$. For each column permutation, the proposed method enables to generate $8!$ clone copies by permuting the rows.

研究の動機と目的

  • 既存の鍵依存Sボックス生成手法における不変代数的性質の欠如に対処すること。
  • 非線形性、SAC、BICといった重要な暗号的性質が動的に生成されたSボックスクローン間で保持される、体系的なアルゴリズムの開発。
  • AES Sボックスなどの単一の強力な初期Sボックスから、複数の安全で鍵依存のSボックス変種を生成すること。
  • 従来の列置換に限られていた先行研究を拡張し、群作用を用いて行の置換を統合すること。
  • 代数的特性が同一であるSボックスクローンを生成する、証明可能に安全で効率的な手法の提供。

提案手法

  • 本手法は、Sボックスのブール関数表現(GF(2ⁿ) → GF(2))の列にSₙ、行にS₂ⁿの対称群作用を適用する。
  • 秘密鍵から導出された置換σ₁とσ₂を用いて、Sボックスのバイナリ行列表現の列と行を再編成する。
  • 変換手順は、Sボックスをバイナリ行列に変換し、置換行列P₁とP₂を列と行に適用した後、行列乗算により新たなSボックスを再構築することを含む。
  • アルゴリズムはMapleで実装されており、置換行列生成、バイナリ行列変換、Sボックス再構築のための手続きが含まれる。
  • 群作用の対称性を活用した形式的証明により、全単射、非線形性、SAC、BICの不変性が保証される。
  • AES Sボックス(n=8)および4×4 Sボックス(n=4)を用いた検証により、それぞれ(4!)² = 576および8!×8!のクローンコピーが生成された。

実験結果

リサーチクエスチョン

  • RQ1鍵依存Sボックスを生成する際、元のSボックスの非線形性、SAC、BICを保持できるか?
  • RQ2行と列の置換を群作用を用いて組み合わせることで、複数のSボックスクローンに全単射および暗号的強度を維持できるか?
  • RQ3行と列の置換をどのように組み合わせれば、多数の暗号的に同等のSボックス変種を生成できるか?
  • RQ4本手法は、列置換のみに限られた先行手法を上回る性能を示すか?
  • RQ51つの強力なSボックス(例:AES)を用いて、同一の特性を持つ多数の安全で動的なSボックスを生成できるか?

主な発見

  • 生成されたすべてのクローンSボックスは、元のSボックスの非線形性を保持している:AES Sボックス(n=8)では112、4×4 Sボックスでも112。
  • 厳密なアバランチ基準(SAC)の平均値は0.504883のまま維持され、最大値は0.5625、最小値は0.453125であり、元のSボックスと同一。
  • 非線形性およびSACにおけるビット独立性基準(BIC)の平均値と標準偏差(0.504604および0.011271)は、元のSボックスとクローンSボックスで同一。
  • n=8の場合、本手法により1つのAES Sボックスから8! × 8! = 1.6×10¹⁰個の異なるSボックスクローンが生成され、すべての代数的性質が同一。
  • n=4の場合、(4!)² = 576個のクローンSボックスが生成され、同一の暗号的特性を有しており、スケーラビリティが確認された。
  • 理論的証明により、全単射、非線形性、SAC、BICが提案された群作用に基づく変換に対して不変であることが確認された。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。