论文部分内容阅读
This paper studies the security of the block ciphers ARIA and Camellia against impossible differential crypt-analysis. Our work improves the best impossible differential cryptanalysis of ARIA and Camellia known so far. The designersof ARIA expected no impossible differentials exist for 4-round ARIA. However, we found some nontrivial 4-round impossibledifferentials, which may lead to a possible attack on 6-round ARIA. Moreover, we found some nontrivial 8-round impossi-ble differentials for Camellia, whereas only 7-round impossible differentials were previously known. By using the 8-roundimpossible differentials, we presented an attack on 12-round Camellia without FL/FL<’-1> layers.