Header menu link for other important links
X
A Chosen IV Related Key Attack on Grain-128a
Subhadeep Banik, Maitra Subhamoy, , Meltem Sönmez Turan
Published in Springer Berlin Heidelberg
2013
Pages: 13 - 26
Abstract

Due to the symmetric padding used in the stream cipher Grain v1 and Grain-128, it is possible to find Key-IV pairs that generate shifted keystreams efficiently. Based on this observation, Lee et al. presented a chosen IV related Key attack on Grain v1 and Grain-128 at ACISP 2008. Later, the designers introduced Grain-128a having an asymmetric padding. As a result, the existing idea of chosen IV related Key attack does not work on this new design. In this paper, we present a Key recovery attack on Grain-128a, in a chosen IV related Key setting. We show that using around γ·232 (γ is a experimentally determined constant and it is sufficient to estimate it as 28) related Keys and γ·264 chosen IVs, it is possible to obtain 32·γ simple nonlinear equations and solve them to recover the Secret Key in Grain-128a.

About the journal
JournalData powered by TypesetInformation Security and Privacy
PublisherData powered by TypesetSpringer Berlin Heidelberg
Open AccessNo