Information Security and Privacy: 19th Australasian by Willy Susilo, Yi Mu

This publication constitutes the refereed convention lawsuits of the nineteenth Australasian convention on info safety and privateness, ACISP 2014, held in Wollongong, NSW, Australia, in July 2014. The 26 revised complete papers and six brief papers provided during this quantity have been rigorously chosen from ninety one submissions. The papers are prepared in topical sections on cryptanalysis; cryptographic protocols; fine-grain cryptographic protocols; key trade, basics, lattices and homomorphic encryption, and applications.

It consists of nonlinear Feistel transformations and linear transformations, which operate on the left and right two words of the encryption/intermediate keys, respectively. The input is a 128-bit encryption key denoted by K(128) . The output consists of six 128-bit round keys and one 64-bit round key, denoted by K (r) (128) (1 ∈ r ∈ 6) and K (7) 1(64) . The 128-bit intermediate keys denoted by Z (r) (128) (0 ∈ r ∈ 7) are generated in the process of the key scheduling operation. The 5th to 7th round functions are the inverse of the 2nd to 4th ones; therefore, the following relationships hold: Z (r) (128) = Z (8−r) (128) (5 ∈ r ∈ 7).

SAC 2000. LNCS, vol. 2012, pp. 39–56. Springer, Heidelberg (2001) 32 B. Taga, S. Moriai, and K. Aoki 2. : New types of cryptanalytic attacks using related keys. J. Cryptology 7(4), 229–246 (1994) 3. : Cryptanalysis of Skipjack Reduced to 31 Rounds Using Impossible Differentials. In: Stern, J. ) EUROCRYPT 1999. LNCS, vol. 1592, pp. 12–23. Springer, Heidelberg (1999) 4. : Miss in the Middle Attacks on IDEA and Khufu. R. ) FSE 1999. LNCS, vol. 1636, pp. 124–138. Springer, Heidelberg (1999) 5. : New Insights on Impossible Differential Cryptanalysis.

Then difference between F (x) and F (xβ ) is deterministically 0 only if all elements of δ are also deterministically 0 (this corresponds to all elements of Δ being 0). If even one element of δ is not deterministically 0 then the difference between F (x) and F (xβ ) becomes probabilistic and depends on the nature of the Boolean Function F (x) ⊕ F (xβ ). In such an event, 2 · OR(Δ) returns 2. Now observe the equation defining πt . Note that Φt consists of tap locations that add linearly to the output function and πt consists of the locations that feed the non-linear h function in the original generalized Grain cipher.

