Analysis of Involutional Ciphers: Khazad and Anubis

9 years 2 months ago
Analysis of Involutional Ciphers: Khazad and Anubis
In this paper we study structural properties of SPN ciphers in which both the S-boxes and the affine layers are involutions. We apply our observations to the recently designed Rijndael-like ciphers Khazad and Anubis, and show several interesting properties of these ciphers. We also show that 5-round Khazad has 264 weak keys under a “slide-witha-twist” attack distinguisher. This is the first cryptanalytic result which is better than exhaustive search for 5-round Khazad. Analysis presented in this paper is generic and applies to a large class of ciphers built from involutional components.
Alex Biryukov
Added 06 Jul 2010
Updated 06 Jul 2010
Type Conference
Year 2003
Where FSE
Authors Alex Biryukov
Comments (0)