An improved distinguisher for Dragon

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

The Dragon stream cipher is one of the focus ciphers which have reached Phase 2 of the eSTREAM project. In this paper, we present a new method of building a linear distinguisher for Dragon. The distinguisher is constructed by exploiting the biases of two S-boxes and the modular addition which are basic components of the nonlinear function F. The bias of the distinguisher is estimated to be around 2(-75.32) which is better than the bias of the distinguisher presented by Englund and Maximov. We have shown that Dragon is distinguishable from a random cipher by using around 2(150.6) keystream words and 2(64) memory. In addition, we present a very efficient algorithm for computing the bias of linear approximation of modular addition.

Original languageEnglish
Title of host publicationCoding and cryptology
Subtitle of host publicationproceedings of the first international workshop Wuyi Mountain, Fujian, China, 11 – 15 June 2007
EditorsYongqing Li, San Ling, Harald Niederreiter, Huaxiong Wang, Chaoping Xing, Shengyuan Zhang
Place of PublicationSingapore; London
PublisherWorld Scientific Publishing
Pages91-108
Number of pages18
Volume4
ISBN (Print)9789812832238
Publication statusPublished - 2008
Event1st International Workshop on Coding and Cryptology - Fujian, China
Duration: 11 Jun 200715 Jun 2007

Publication series

NameSeries on coding theory and cryptology
PublisherWorld Scientific Publishing Co.
Volume4
ISSN (Print)1793-2238

Conference

Conference1st International Workshop on Coding and Cryptology
Country/TerritoryChina
CityFujian
Period11/06/0715/06/07

Keywords

  • Stream Ciphers
  • eSTREAM
  • Dragon
  • Distinguishing Attacks
  • Modular Addition

Fingerprint

Dive into the research topics of 'An improved distinguisher for Dragon'. Together they form a unique fingerprint.

Cite this