在传统的积分密码分析中,积分区分器都是以概率1成立的.虽然Knudsen等学者提到过:“就像差分一样,积分也可以是概率的”,但是,没有文献报道过进一步的研究.文中对此问题进行了探讨,提出了概率积分密码分析方法,并从理论和实验两方面验证了概率积分分析方法的有效性.对于采用S盒设计的分组密码,文中证明了如果s盒的差分均匀性越接近随机概率,则分组密码抵抗概率积分密码分析的能力就越强.同时,文中指出高阶积分分析的某些技巧对于概率积分分析是行不通的,主要原因是随着求和变量个数的增加,积分特征概率趋近于随机概率.最后,文中通过对AES和LBlock这两个算法的概率积分分析实例,说明目前广泛使用的分组密码算法对于概率积分密码分析方法都是免疫的.
In traditional integral cryptanalysis, the integral distinguisher was with probability 1. Knudsen once mentioned: "Integrals can be probabilistic just like differentials", but there was no further research afterwards. In this paper, we study deeply into this problem. Firstly, we intro- duce the method of Probabilistic Integral Cryptanalysis, and then we testify the validity of this method both in theory and experiment. For block cipher which contains S-boxes, it is proved that the closer the differential uniformity of S-boxes gets to random probability, the stronger the resistance of the block cipher to probabilistic integral cryptanalysis is. Finally, we point out that the techniques of higher order differential cryptanalysis do not work in probabilistic integral cryptanalysis, for the reason that the probability of integral characteristic regresses toward the random probability with increment of the number of sum variables. Furthermore, after the exper- imental probabilistic integral cryptanalysis of two block ciphers LBlock and AES, we come to a conclusion that most of existing modern block ciphers is immune to probabilistic integral crypta- nalysis.