Improved Correlation Attacks on SOSEMANUK and SOBER-128
Joo Yeon Cho
Helsinki University of Technology Department of Information and Computer Science, Espoo, Finland
24th March 2009
1 / 35
Improved Correlation Attacks on SOSEMANUK and SOBER-128 Joo Yeon - - PowerPoint PPT Presentation
Improved Correlation Attacks on SOSEMANUK and SOBER-128 Joo Yeon Cho Helsinki University of Technology Department of Information and Computer Science, Espoo, Finland 24th March 2009 1 / 35 SOSEMANUK Attack Approximations SOBER-128
1 / 35
SOSEMANUK Attack Approximations SOBER-128
2 / 35
SOSEMANUK Attack Approximations SOBER-128
3 / 35
SOSEMANUK Attack Approximations SOBER-128
4 / 35
SOSEMANUK Attack Approximations SOBER-128
5 / 35
SOSEMANUK Attack Approximations SOBER-128
6 / 35
SOSEMANUK Attack Approximations SOBER-128
7 / 35
SOSEMANUK Attack Approximations SOBER-128
8 / 35
SOSEMANUK Attack Approximations SOBER-128
9 / 35
SOSEMANUK Attack Approximations SOBER-128
10 / 35
SOSEMANUK Attack Approximations SOBER-128
11 / 35
SOSEMANUK Attack Approximations SOBER-128
NS0
N
12 / 35
SOSEMANUK Attack Approximations SOBER-128
13 / 35
SOSEMANUK Attack Approximations SOBER-128
14 / 35
SOSEMANUK Attack Approximations SOBER-128
15 / 35
SOSEMANUK Attack Approximations SOBER-128
16 / 35
SOSEMANUK Attack Approximations SOBER-128
17 / 35
SOSEMANUK Attack Approximations SOBER-128
18 / 35
SOSEMANUK Attack Approximations SOBER-128
19 / 35
SOSEMANUK Attack Approximations SOBER-128
20 / 35
SOSEMANUK Attack Approximations SOBER-128
21 / 35
SOSEMANUK Attack Approximations SOBER-128
22 / 35
SOSEMANUK Attack Approximations SOBER-128
23 / 35
SOSEMANUK Attack Approximations SOBER-128
l−m 2 /(M × csose2)
24 / 35
SOSEMANUK Attack Approximations SOBER-128
l−m 2 /(M × c2
25 / 35
SOSEMANUK Attack Approximations SOBER-128
26 / 35
SOSEMANUK Attack Approximations SOBER-128
27 / 35
SOSEMANUK Attack Approximations SOBER-128
28 / 35
SOSEMANUK Attack Approximations SOBER-128
ω(H) ω(H) : most sig. byte of ω ω′
(H)
ω′
(H) : most sig. byte of ω′
29 / 35
SOSEMANUK Attack Approximations SOBER-128
30 / 35
SOSEMANUK Attack Approximations SOBER-128
2^20 2^21 2^22 2^23 2^24 2^25 2^26 2^27 2^28 −0.01 −0.008 −0.006 −0.004 −0.002 0.002 0.004 0.006 0.008 0.01
number of texts correlation Empirical Test of Correlations of SOBER−128
31 / 35
SOSEMANUK Attack Approximations SOBER-128
l−m 2 /(M × c2
32 / 35
SOSEMANUK Attack Approximations SOBER-128
33 / 35
SOSEMANUK Attack Approximations SOBER-128
34 / 35
SOSEMANUK Attack Approximations SOBER-128
35 / 35