2
by John Kelsey, Bruce Schneier, David Wagner
http://www.cs.berkeley.edu/~daw/papers/speed-sac98.ps
Add To MetaCart
Abstract:
Abstract. The cipher family SPEED (and an associated hashing mode) was recently proposed in Financial Cryptography '97. This paper cryptanalyzes that proposal, in two parts: First, we discuss several troubling potential weaknesses in the cipher. Next, we show how to efficiently break the SPEED hashing mode using differential related-key techniques, and propose a differential attack on 48-round SPEED. These results raise some significant questions about the security of the SPEED design. 1
Citations
| 200 | The RC5 encryption algorithm – Rivest - 1995 |
| 108 | New types of cryptanalytic attacks using related keys – Biham - 1993 |
| 92 | Markov ciphers and differential cryptanalysis – Lai, Massey, et al. |
| 36 | Key-schedule cryptanalysis of – Kelsey, Schneier, et al. - 1996 |
| 33 | Improved Cryptanalysis of RC5 – Biryukov, Kushilevitz - 1998 |
| 33 | Unbalanced Feistel Networks and Block Cipher Design – Schneier, Kelsey - 1996 |
| 20 | Fast Software Encryption: Designing Encryption Algorithms for Optimal Speed on – Schneier, Whiting - 1997 |
| 15 | Recent developments in the design of conventional cryptographic algorithms – Preneel, Rijmen, et al. - 1998 |
| 14 | On the design and security of RC2 – Knudsen, Rijmen, et al. - 1998 |
| 14 | On weaknesses of non-surjective round functions – Rijmen, Preneel, et al. - 1997 |
| 11 | The SPEED Cipher – Zheng - 1997 |
| 10 | Chosen-key Attacks on a Block Cipher – Winternitz, Hellman - 1987 |

