SMS4是中国官方公布的第一个商用分组密码标准,使用差分方法分析了18轮的SMS4差分特征,并在此基础上攻击了22一轮的SMS4,攻击过程需要2^117个选择明文,2^112字节的存储空间,而时间复杂度为2^123次22一轮加密。此结果是目前对SMS4差分分析的最好结果。
SMS4 is a 128-bit block cipher used in WAPI, the Chinese WLAN national standard. A new 18-round differential characteristic of SMS4 is presented, basing on which the 22-round SMS4 is at- tacked. The attack requires 2^117 chosen plaintexts, 2^112 bytes of memory and 2^123 22-round encryptions. And the attack is the best differential cryptanalytic result on SMS4.