1,721,112 research outputs found

    Resistance of SNOW-V against Fast Correlation Attacks

    Get PDF
    SNOW-V is a new member in the SNOW family of stream ciphers, hoping to be competitive in the 5G mobile communication system. In this paper, we study the resistance of SNOW-V against bitwise fast correlation attacks by constructing bitwise linear approximations. First, we propose and summarize some efficient algorithms using the slice-like techniques to compute the bitwise linear approximations of certain types of composition functions composed of basic operations like ⊞, ⊕, Permutation, and S-box, which have been widely used in word-oriented stream ciphers such as SNOW-like ciphers. Then, using these algorithms, we find a number of stronger linear approximations for the FSM of the two variants of SNOW-V given in the design document, i.e., SNOW-V σ0 and SNOW-V⊞8, ⊞8. For SNOW-V σ0, where there is no byte-wise permutation, we find some bitwise linear approximations of the FSM with the SEI (Squared Euclidean Imbalance) around 2−37.34 and mount a bitwise fast correlation attack with the time complexity 2251.93 and memory complexity 2244, given 2103.83 keystream outputs, which improves greatly the results in the design document. For SNOW-V⊞8, ⊞8, where both of the two 32-bit adders in the FSM are replaced by 8-bit adders, we find our best bitwise linear approximations of the FSM with the SEI 2−174.14, while the best byte-wise linear approximation in the design document of SNOW-V has the SEI 2−214.80. Finally, we study the security of a closer variant of SNOW-V, denoted by SNOW-V⊞32, ⊞8, where only the 32-bit adder used for updating the first register is replaced by the 8-bit adder, while everything else remains identical. For SNOW-V⊞32, ⊞8, we derive many mask tuples yielding the bitwise linear approximations of the FSM with the SEI larger than 2−184. Using these linear approximations, we mount a fast correlation attack with the time complexity 2377.01 and a memory complexity 2363, given 2253.73 keystream outputs. Note that neither of our attack threatens the security of SNOW-V. We hope our research could further help in understanding bitwise linear approximation attacks and also the structure of SNOW-like stream ciphers

    Алгебраїчна атака на двiйковi SNOW-V-подiбнi потоковi шифри

    Get PDF
    У статтi представлено опис двiйкових SNOW-V-подiбних потокових шифрiв, а також адаптацiя вже iснуючих алгебраїчних атак на двiйковi версiї попередника – потокового шифру SNOW2.0, що дозволить застосовувати їх до двiйкових SNOW-V-подiбних потокових шифрiв

    Алгебраїчна атака на двійковій SNOW-V-подібний потоковий шифр

    Get PDF
    У цiй роботi зроблен детальний аналiз архiтектури потокового шифру SNOW-V, вплив компонент шифру на стiйкiсть шифру до рiзноманiтних атак, введено поняття двiйкових SNOW-V-подiбних потокових шифрiв, запропоновано адаптацiю атаки на двiйковi SNOW2.0-подiбнi потоковi шифри до атаки на двiйковi SNOW-V-подiбнi потоковi шифри та проведено аналiз результатiв i визначено параметри системи рiвнянь, що впливаю на стiйкiсть до цiєї атаки. Тема роботи: алгебраїчна атака на двiйковi SNOW-V-подiбнi потоковi шифри. Мета роботи: визначення параметрiв систем нелiнiйних рiвнянь, що мають вплив на стiйкiсть потокових шифрiв до наведеної у роботi алгебраїчної атаки на двiйковi SNOW-V-подiбнi потоковi шифри Задача роботи: адаптацiя вiдомих алгебраїчних атак на модифiкацiї SNOW2.0 до атаки на двiйковi SNOW-V-подiбнi потоковi шифри та формування умов стiйкостi цього шифру до заданої атаки. Об’єкт дослiдження: процес перетворення iнформацiї у двiйкових SNOW-V-подiбних потокових шифрах. Предмет дослiдження: властивостi складових частин алгоритмiв потокового шифрування, якi зумовлюють їх стiйкiсть до алгебраїчних атак. Методи дослiдження: методи теорiї абстрактної алгебри, булевих функцiй, кодування та обчислення. У результатi цiєї роботи запропоновано адаптацiю атаки на двiйковi SNOW2.0-подiбнi потоковi шифри до атаки на двiйковi SNOW-V-подiбнi потоковi шифри та проведено аналiз результатiв i визначено параметри системи рiвнянь, що впливають на стiйкiсть та дозволяють провести оцiнку 5 трудоємностi заданої атаки. Результати цiєї роботи були частково представленi на XIX Науково-практичнiй конференцiї студентiв, аспiрантiв та молодих вчених "Теоретичнi i прикладнi проблеми фiзики, математики та iнформатики"на базi Фiзико-технiчного iнституту Нацiонального технiчного унiверситету України “Київський полiтехнiчний iнститут iменi Iгоря Сiкорського” (13-14 травня 2021р., м. Київ).This thesis provides a detailed analysis of the architecture of the SNOW-V stream cipher, the influence of cipher components on the resistance of this cipher to various attacks, introduced the concept of binary SNOW-V-type stream ciphers, proposed adaptation of the attack on binary SNOW2.0-type stream ciphers to attack on binary SNOW-V-type stream ciphers and analyzed the results and determined the parameters of the system of equations that affect the resistance to this attack. The theme of this thesis is an algebraic attack on binary SNOW-V-type stream ciphers. The goal of this thesis is to determine the parameters of systems of nonlinear equations that affect the stability of stream ciphers to the algebraic attack on binary SNOW-V-type stream ciphers. The task of this work is adaptation of known algebraic attacks on modification of the cipher SNOW2.0 to attack on binary SNOW-V-type stream ciphers and formation of conditions of resistance of this cipher to the attack. The object of the process of converting information in binary SNOW-Vtype streaming ciphers. The subject of the research are properties of components of streaming encryption algorithms, which determine their resistance to algebraic attacks. Methods of research are methods of the theory of abstract algebra, boolean functions, coding and calculation. As a result of this work, the adaptation of the attack on binary SNOW2.0- type stream ciphers to the attack on binary SNOW-V-like stream ciphers is proposed and the results are analyzed and the parameters of the system of equations influencing stability and estimating the complexity of a given attack are determined. 9 The results of this work were partially presented at the XIX Scientific and Practical Conference of Students, Postgraduates and Young Scientists "Theoretical and Applied Problems of Physics, Mathematics and Computer science"on the basis of the Institute of Physics and Technology of the National Technical University of Ukraine "Kyiv Polytechnic Institute"(May 13-14 2021, Kyiv)

    A Correlation Attack on Full SNOW-V and SNOW-Vi

    Get PDF
    In this paper, a method for searching correlations between the binary stream of Linear Feedback Shift Register (LFSR) and the keystream of SNOW-V and SNOW-Vi is presented based on the technique of approximation to composite functions. With the aid of the linear relationship between the four taps of LFSR input into Finite State Machine (FSM) at three consecutive clocks, we present an automatic search model based on the SAT/SMT technique and search out a series of linear approximation trails with high correlation. By exhausting the intermediate masks, we find a binary linear approximation with a correlation 247.76-2^{-47.76}. Using such approximation, we propose a correlation attack on SNOW-V with an expected time complexity 2246.532^{246.53}, a memory complexity 2238.772^{238.77} and 2237.52^{237.5} keystream words generated by the same key and Initial Vector (IV). For SNOW-Vi, we provide a binary linear approximation with the same correlation and mount a correlation attack with the same complexity as that of SNOW-V. To the best of our knowledge, this is the first known attack on full SNOW-V and SNOW-Vi, which is better than the exhaustive key search with respect to time complexity. The results indicate that neither SNOW-V nor SNOW-Vi can guarantee the 256-bit security level if we ignore the design constraint that the maximum length of keystream for a single pair of key and IV is less than 2642^{64}

    Análisis e implementación del SNOW-V

    Get PDF
    El objetivo de este Trabajo de Fin de Grado consiste en realizar un análisis completo del generador de SNOW-V, cuyos autores pretenden que sea implementado como cifrado primitivo en sistemas de telefonía móvil 5G. Para ello, se implementó este cifrado de flujo y se estudiaron diferentes técnicas software para mejorar su eficiencia y cotejarlas con la implementación que viene implícita en el algoritmo y poder sacar conclusiones. Estas posibles mejoras se compararon en dos plataformas con diferentes características, siendo la primera un portátil de gama media y la segunda un IDE online que tiene unas prestaciones altas, para así analizar cómo se comporta el algoritmo en diferentes entornos. Los resultados obtenidos demuestran que la implementación Tradicional de SNOW-V no es la más eficiente, siendo la modificación de Ventanas Deslizantes la óptima en ambas plataformas.The objective of this Final Degree Project is to carry out a complete analysis of the SNOW-V generator, whose authors intend it to be implemented as the primitive encryption in 5G mobile systems. For this, this stream cipher was implemented and different software techniques were studied to improve its efficiency and compare them with the implementation that is implicit in the algorithm to draw conclusions. These possible improvements were compared on two platforms with different characteristics, the first being a mid-range laptop and the second an online IDE with high performance, in order to analyze how the algorithm behaves in different environments. The results obtained show that the Traditional implementation of SNOW-V is not the most efficient, being the Sliding Windows modification the optimal one in both platforms

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis

    Efficient and Extensive Search Linear Approximations with High for Precise Correlations of Full SNOW-V

    No full text
    SNOW-V is a stream cipher recently designed for 5G communication system. In this paper, we propose two efficient algorithms to evaluate the precise correlation of SNOW-V\u27s two main nonlinear components with linear hull effects fully considered. Based on these algorithms, we could efficiently and extensively search much more linear masks than before. The ideas of these algorithms can be generalized to other similar nonlinear components in symmetric cipher. We apply our algorithms to full SNOW-V to search different types of linear approximations with high correlations. Our results depict more linear approximations with higher correlations than those proposed for full SNOW-V and SNOW-V32,8\text{V}_{\boxplus_{32},\boxplus_8} recently. The best linear approximation we found has absolute correlation 247.5672^{-47.567}. There are at least 8, 135 and 1092 linear approximations with absolute correlation greater than 247.8512^{-47.851}, 2492^{-49} and 2502^{-50} respectively, which would derive a fast correlation attack with time/memory/data complexities 2240.862^{240.86}, 2240.372^{240.37} and 2236.872^{236.87}. It is better than all the previous results of fast correlation attack against full SNOW-V. Moreover, we propose some properties for linear trails with 3 active S-boxes, which give a theoretical explanation that automatic search method lacks of. Our work provides a more comprehensive description for the linear approximation properties of full SNOW-V
    corecore