{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,6,1]],"date-time":"2024-06-01T05:50:18Z","timestamp":1717221018869},"reference-count":25,"publisher":"Oxford University Press (OUP)","issue":"9","license":[{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"funder":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing","award":["2018A03"],"award-info":[{"award-number":["2018A03"]}]},{"name":"National Cryptography Development Fund","award":["MMJJ20180203"],"award-info":[{"award-number":["MMJJ20180203"]}]},{"name":"Henan Key Laboratory of Network Cryptography Technology","award":["LNCT-2019-S03"],"award-info":[{"award-number":["LNCT-2019-S03"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,9,16]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Deoxys-BC is an internal tweakable block cipher of the authenticated encryption algorithm Deoxys, which is a third-round finalist in the CAESAR competition. In this paper, we study the property of Deoxys-BC, such as the subtweakey difference cancelation and the freedom of the tweak. Combining the differential enumeration technique with these properties, the authors achieve the key-recovery attacks on Deoxys-BC under the meet-in-the-middle attack. As a result, we get an attack on 9-round Deoxys-BC-128-128 by constructing a 6-round meet-in-the-middle distinguisher with $2^{113}$ plaintext\u2013tweak combinations, $2^{97}$ Deoxys-BC blocks and $2^{121.6}$ 9-round Deoxys-BC-128-128 encryptions. We also present an attack on 11-round Deoxys-BC-256-128 for the first time by constructing a 7-round meet-in-the-middle distinguisher with $2^{113}$ plaintext-tweak combinations, $2^{226}$ Deoxys-BC blocks and $2^{251}$ 11-round Deoxys-BC-256-128 encryptions.<\/jats:p>","DOI":"10.1093\/comjnl\/bxab076","type":"journal-article","created":{"date-parts":[[2021,5,7]],"date-time":"2021-05-07T11:38:08Z","timestamp":1620387488000},"page":"2411-2420","source":"Crossref","is-referenced-by-count":2,"title":["Improved Meet-in-the-Middle Attacks on Reduced-Round Tweakable Block Cipher Deoxys-BC"],"prefix":"10.1093","volume":"65","author":[{"given":"Manman","family":"Li","sequence":"first","affiliation":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing , 62 Kexue Road, 450001 Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shaozhen","family":"Chen","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing , 62 Kexue Road, 450001 Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2021,6,2]]},"reference":[{"key":"2022091610474317100_ref1","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1007\/3-540-45708-9_3","volume-title":"Tweakable Block Ciphers. In Advances in Cryptology CRYPTO 2002","author":"Liskov","year":"2002"},{"key":"2022091610474317100_ref2","volume-title":"Deoxys v1.41","author":"Jean","year":"2016"},{"key":"2022091610474317100_ref3","volume-title":"Tweaks and keys for block ciphers: The TWEAKEY framework","author":"Jean","year":"2014"},{"key":"2022091610474317100_ref4","doi-asserted-by":"crossref","first-page":"645","DOI":"10.1007\/s10623-013-9882-8","article-title":"Building blockcipher from small-block tweakable blockcipher","volume":"74","author":"Minematsu","year":"2015","journal-title":"Des. Codes Cryptogr."},{"key":"2022091610474317100_ref5","doi-asserted-by":"crossref","first-page":"73","DOI":"10.46586\/tosc.v2017.i3.73-107","article-title":"Cryptanalysis of Deoxys and its internal tweakable block ciphers","volume":"3","author":"Cid","year":"2017","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2022091610474317100_ref6","volume-title":"Impossible differential cryptanalysis on Deoxys-BC-256","author":"Mehrdad","year":"2018"},{"key":"2022091610474317100_ref7","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1049\/iet-ifs.2018.5091","article-title":"Meet-in-the-middle attacks on round-reduced tweakable block cipher Deoxys-BC","volume":"13","author":"Li","year":"2019","journal-title":"IET Inf. Secur."},{"key":"2022091610474317100_ref8","doi-asserted-by":"crossref","first-page":"121","DOI":"10.46586\/tosc.v2019.i3.121-151","article-title":"New related-tweakey boomerang and rectangle attacks on Deoxys-BC including BDT effect","volume":"3","author":"Zhao","year":"2019","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2022091610474317100_ref9","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1007\/978-3-030-35423-7_7","article-title":"Improved Related-Tweakey Rectangle Attacks on Reduced-Round Deoxys-BC-384 and Deoxys-I-256-128","volume-title":"INDOCRYPT 2019","author":"Zhao","year":"2019"},{"key":"2022091610474317100_ref10","doi-asserted-by":"crossref","first-page":"1859","DOI":"10.1093\/comjnl\/bxaa028","article-title":"Improved meet-in-the-middle attacks on reduced-round Deoxys-BC-256","volume":"63","author":"Liu","year":"2020","journal-title":"Comput. J."},{"key":"2022091610474317100_ref11","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1109\/C-M.1977.217750","article-title":"Exhaustive cryptanalysis of the NBS data encryption standard","volume":"10","author":"Diffie","year":"1977","journal-title":"Computer"},{"key":"2022091610474317100_ref12","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1007\/978-3-642-19574-7_16","article-title":"A 3-Subset Meet-in-the-Middle Attack: Cryptanalysis of the Lightweight Block Cipher KTANTAN","volume-title":"Selected Areas in Cryptography-SAC10","author":"Bogdanov","year":"2011"},{"key":"2022091610474317100_ref13","first-page":"272","article-title":"KATAN and KTANTAN: A Family of Small and Efficient Hardware-Oriented Block Ciphers","volume-title":"Cryptographic Hardware and Embedded System\u2014CHES09","author":"Canniere","year":"2009"},{"key":"2022091610474317100_ref14","doi-asserted-by":"crossref","first-page":"244","DOI":"10.1007\/978-3-642-34047-5_15","article-title":"Bicliques for Preimages: Attacks on Skein-512 and the SHA-2 Family","volume-title":"Fast Software Encryption-FSE12","author":"Khovratovich","year":"2012"},{"key":"2022091610474317100_ref15","first-page":"344","article-title":"Biclique Cryptanalysis of the Full AES","volume-title":"ASIACRYPT11","author":"Bogdanov","year":"2011"},{"key":"2022091610474317100_ref16","first-page":"464","article-title":"Generic Key Recovery Attack on Feistel Scheme","volume-title":"ASIACRYPT13","author":"Isobe","year":"2013"},{"key":"2022091610474317100_ref17","doi-asserted-by":"crossref","first-page":"116","DOI":"10.1007\/978-3-540-71039-4_7","article-title":"A Meet-in-the-Middle Attack on 8-Round AES","volume-title":"Fast Software Encryption-FSE08","author":"Demirci","year":"2008"},{"key":"2022091610474317100_ref18","first-page":"158","article-title":"Improved Single-Key Attacks on 8-Round AES-192 and AES-256","volume-title":"ASIACRYPT10","author":"Dunkelman","year":"2010"},{"key":"2022091610474317100_ref19","first-page":"371","article-title":"Improved Key Recovery Attacks on Reduced-Round AES","volume-title":"EUROCRYPT13","author":"Derbez","year":"2013"},{"key":"2022091610474317100_ref20","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1007\/978-3-662-46706-0_7","article-title":"Improved Single-Key Attacks on 9-Round AES-192\/256","volume-title":"Fast Software Encryption-FSE14","author":"Li","year":"2015"},{"key":"2022091610474317100_ref21","first-page":"157","article-title":"Automatic Search of Meet-in-the-Middle and Impossible Differential Attacks","volume-title":"CRYPTO16 (Part II)","author":"Derbez","year":"2016"},{"key":"2022091610474317100_ref22","doi-asserted-by":"crossref","first-page":"190","DOI":"10.1007\/978-3-662-48116-5_3","article-title":"Meet-in-the-Middle Technique for Truncated Differential and Its Applications to CLEFIA and Camellia","volume-title":"Fast Software Encryption-FSE15","author":"Li","year":"2015"},{"key":"2022091610474317100_ref23","first-page":"2","article-title":"Differential Cryptanalysis of DES\u2013Like Cryptosystems","volume-title":"CRYPTO90","author":"Biham","year":"1990"},{"key":"2022091610474317100_ref24","first-page":"168","article-title":"Practical Security Evaluation against Differential and linear Attacks for Feistel Ciphers with SPN Round Function","volume-title":"Selected Areas in Cryptography, SAC00","author":"Kanda","year":"2000"},{"key":"2022091610474317100_ref25","doi-asserted-by":"crossref","first-page":"32102","DOI":"10.1007\/s11432-017-9382-2","article-title":"Related-tweakey impossible differential attack on reduced-round Deoxys-BC-256","volume":"62","author":"Zong","year":"2019","journal-title":"Sci. China Inform. Sci."}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/65\/9\/2411\/45882128\/bxab076.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/65\/9\/2411\/45882128\/bxab076.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,16]],"date-time":"2022-09-16T10:48:28Z","timestamp":1663325308000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/65\/9\/2411\/6291059"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,2]]},"references-count":25,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2021,6,2]]},"published-print":{"date-parts":[[2022,9,16]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxab076","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2022,9]]},"published":{"date-parts":[[2021,6,2]]}}}