Multi-differential cryptanalysis on reduced DM-PRESENT-80: collisions and other differential properties

  • Authors:
  • Takuma Koyama;Yu Sasaki;Noboru Kunihiro

  • Affiliations:
  • The University of Tokyo, Kashiwa-shi, Chiba, Japan;NTT Secure Platform Laboratories, NTT Corporation, Musashino-shi, Tokyo, Japan;The University of Tokyo, Kashiwa-shi, Chiba, Japan

  • Venue:
  • ICISC'12 Proceedings of the 15th international conference on Information Security and Cryptology
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

The current paper studies differential properties of the compression function of reduced-round DM-PRESENT-80, which was proposed at CHES 2008 as a lightweight hash function with 64-bit digests. Our main result is a collision attack on 12 rounds with a complexity of 229.18 12-round DM-PRESENT computations. Then, the attack is extended to an 18-round distinguisher and an 12-round second preimage attack. In our analysis, the differential characteristic is satisfied by the start-from-the-middle approach. Our success lies in the detailed analysis of the data transition, where the internal state and message values are carefully chosen so that a differential characteristic for 5 rounds can be satisfied with complexity 1 on average. In order to reduce the attack complexity, we consider as many techniques as possible; multi-inbound technique, early aborting technique, precomputation of look-up tables, multi-differential characteristics.