{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T00:39:06Z","timestamp":1778546346855,"version":"3.51.4"},"reference-count":22,"publisher":"Oxford University Press (OUP)","issue":"8","license":[{"start":{"date-parts":[[2020,12,21]],"date-time":"2020-12-21T00:00:00Z","timestamp":1608508800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61572516"],"award-info":[{"award-number":["61572516"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61272041"],"award-info":[{"award-number":["61272041"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61272488"],"award-info":[{"award-number":["61272488"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,8,25]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>The K2 stream cipher, designed for 32-bit words, is an ISO\/IEC 18033 standard and is listed as a recommended algorithm used by the Japanese government in the CRYPTREC project. The main feature of the K2 algorithm is the use of a dynamic feedback control mechanism between the two linear feedback shift registers, which makes the analysis of the K2 algorithm more difficult. In this paper, for its simplified version algorithm, a key recovery attack is performed by using differential attacks. Firstly, for the unknown key, the same IV is fixed in two chosen IV differential attacks, and we use the input differences and the output differences of the S-box to recover the input of S-box; the internal state values can be uniquely determined by taking intersection of the input of S-box. This technology is used to improve the key recovery attack of seven-round algorithm proposed by Deike Priemuth-Schmid. Secondly, we find the constraint relationship between the keystream equations and the unknown differences by introducing the guess difference bit and eliminate the impossible differences by the constraint relationship. Thus, we expand the key recovery attack from seven to nine rounds. The time complexity of the attack is $\\boldsymbol{O} \\boldsymbol{(2^{113.93})}$, the data complexity is $\\boldsymbol{O}\\boldsymbol{(2^{8.71})}$ and the success rate is $\\textbf{99.07\\%}$.<\/jats:p>","DOI":"10.1093\/comjnl\/bxaa154","type":"journal-article","created":{"date-parts":[[2020,10,13]],"date-time":"2020-10-13T11:38:13Z","timestamp":1602589093000},"page":"1253-1263","source":"Crossref","is-referenced-by-count":6,"title":["Improved Key Recovery Attacks on Simplified Version of K2 Stream Cipher"],"prefix":"10.1093","volume":"64","author":[{"given":"Sudong","family":"Ma","sequence":"first","affiliation":[{"name":"Strategic Support Force Information Engineering University, Zhengzhou450001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jie","family":"Guan","sequence":"additional","affiliation":[{"name":"Strategic Support Force Information Engineering University, Zhengzhou450001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2020,12,21]]},"reference":[{"key":"2021082513002510200_ref1","first-page":"204","article-title":"K2: A Stream Cipher Algorithm Using Dynamic Feedback Control","volume-title":"Proc. SECRYPT 2007","author":"Kiyomoto","year":"2007"},{"key":"2021082513002510200_ref2","first-page":"47","article-title":"A New Version of the Stream Cipher SNOW","volume-title":"Selected Areas in Cryptography, 9th Annual Int. Workshop, SAC 2002","author":"Ekdahl","year":"2002"},{"key":"2021082513002510200_ref3","volume-title":"Specification of the 3GPP confidentiality and integrity algorithms UEA2 & UIA2. Document 2: SNOW 3G specification","author":"SAGE","year":"2006"},{"key":"2021082513002510200_ref4","doi-asserted-by":"crossref","first-page":"1","DOI":"10.46586\/tosc.v2019.i3.1-42","article-title":"A new SNOW stream cipher called SNOW-V","volume":"2020","author":"Ekdahl","year":"2019","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2021082513002510200_ref5","first-page":"222","article-title":"A Distinguishing Attack of SNOW 2.0 with Linear Masking Method","volume-title":"ProcSelected Areas in Cryptography (SAC)","author":"Dai","year":"2003"},{"key":"2021082513002510200_ref6","first-page":"144","article-title":"Improved Linear Distinguishers for SNOW 2.0","volume-title":"Fast Software Encryption, 13th Int. Workshop, FSE 2006","author":"Nyberg","year":"2006"},{"key":"2021082513002510200_ref7","first-page":"249","article-title":"Vectorized linear approximations for attacks on SNOW 3G","volume":"2020","author":"Yang","year":"2019","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2021082513002510200_ref8","doi-asserted-by":"crossref","first-page":"643","DOI":"10.1007\/978-3-662-47989-6_31","article-title":"Fast Correlation Attacks over Extension Fields, Large-Unit Linear Approximation and Cryptanalysis of SNOW 2.0","volume-title":"Proc. Advances in Cryptology\u2014CRYPTO 2015","author":"Zhang","year":"2015"},{"key":"2021082513002510200_ref9","doi-asserted-by":"crossref","first-page":"1324","DOI":"10.3724\/SP.J.1001.2013.04287","article-title":"Guess and determine attack on SNOW 3G and ZUC","volume":"24","author":"Guan","year":"2013","journal-title":"J. Softw."},{"key":"2021082513002510200_ref10","first-page":"37","article-title":"Guess-and-Determine Attacks on SNOW","volume-title":"Selected Areas in Cryptography, 9th Annual Int. Workshop, SAC 2002","author":"Hawkes","year":"2002"},{"key":"2021082513002510200_ref11","article-title":"A guess-and-determine attack on SNOW-V stream cipher","author":"Lin","year":"2020","journal-title":"Comput. J."},{"key":"2021082513002510200_ref12","first-page":"147","article-title":"Differential Resynchronization Attacks on Reduced Round SNOW 3G$^{\\oplus }$","volume-title":"Proc. e-Business and Telecommunications\u20147th Int. Joint Conf., ICETE 2010","author":"Alex","year":"2010"},{"key":"2021082513002510200_ref13","first-page":"139","article-title":"Multiset Collision Attacks on Reduced-Round SNOW 3G and SNOW3G$^{\\oplus }$","volume-title":"Proc. Applied Cryptography and Network Security (ACNS) 2010","author":"Alex","year":"2010"},{"key":"2021082513002510200_ref14","doi-asserted-by":"crossref","first-page":"587","DOI":"10.1049\/iet-ifs.2019.0478","article-title":"Differential attacks on reduced-round SNOW 3G and SNOW 3G$^{\\oplus }$","volume":"14","author":"Ma","year":"2020","journal-title":"IET Inform. Secur."},{"key":"2021082513002510200_ref15","first-page":"43","article-title":"Fast implementation of KCipher-2 for software and hardware","volume":"97","year":"2014","journal-title":"IEICE Trans. Inf. Syst."},{"key":"2021082513002510200_ref16","volume-title":"Information Technology-Security techniques-Encryption algorithms-Part 4: Stream ciphers"},{"key":"2021082513002510200_ref17","volume-title":"Specifications of e-government recommended ciphers","author":"CRYPTREC (2013)"},{"key":"2021082513002510200_ref18","volume-title":"Security evaluation of the K2 stream cipher","author":"Bogdanov","year":"2011"},{"key":"2021082513002510200_ref19","first-page":"117","article-title":"Attacks on Simplified Versions of K2","volume-title":"Int. Joint Conf. Security and Intelligent Information Systems","author":"Priemuth-Schmid","year":"2011"},{"key":"2021082513002510200_ref20","volume-title":"Analysis of Resynchronization Mechanisms of Stream Ciphers","author":"Priemuth-Schmid","year":"2011"},{"key":"2021082513002510200_ref21","first-page":"53","article-title":"Side-Channel Analysis of the K2 Stream Cipher","volume-title":"ACISP 2010","author":"Henricksen","year":"2010"},{"key":"2021082513002510200_ref22","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-662-04722-4","volume-title":"The Design of Rijndael: AES\u2014The Advanced Encryption Standard","author":"Daemen","year":"2002"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/academic.oup.com\/comjnl\/article-pdf\/64\/8\/1253\/39904316\/bxaa154.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"http:\/\/academic.oup.com\/comjnl\/article-pdf\/64\/8\/1253\/39904316\/bxaa154.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,25]],"date-time":"2021-08-25T13:00:48Z","timestamp":1629896448000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/64\/8\/1253\/6042244"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,21]]},"references-count":22,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2020,12,21]]},"published-print":{"date-parts":[[2021,8,25]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxaa154","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2021,8]]},"published":{"date-parts":[[2020,12,21]]}}}