Weak Keys for IDEA (original) (raw)

Abstract

Large classes of weak keys have been found for the block cipher algorithm IDEA, previously known as IPES [2]. IDEA has a 128-bit key and encrypts blocks of 64 bits. For a class of 223 keys IDEA exhibits a linear factor. For a certain class of 235 keys the cipher has a global characteristic with probability 1. For another class of 251 keys only two encryptions and solving a set of 16 nonlinear boolean equations with 12 variables is sufficient to test if the used key belongs to this class. If it does, its particular value can be calculated efficiently. It is shown that the problem of weak keys can be eliminated by slightly modifying the key schedule of IDEA.

Chapter PDF

Similar content being viewed by others

References

  1. X. Lai and J.L. Massey, A Proposal for a New Block Encryption Standard, Advances in Cryptology-Eurocrypt’ 90, Springer-Verlag, Berlin 1991, pp. 389–404.
    Google Scholar
  2. X. Lai, J.L. Massey and S. Murphy, Markov Ciphers and Differential Cryptanalysis, Advances in Cryptology-Eurocrypt’ 91, Springer-Verlag, Berlin 1991, pp. 17–38.
    Google Scholar
  3. E. Biham and A. Shamir, Differential Cryptanalysis of DES-like Cryptosystems, Journal of Cryptology, Springer-Verlag, Vol. 4, No. 1, pp. 3–72, 1991.
    Article MATH MathSciNet Google Scholar
  4. D. Chaum, J.-H. Evertse, Cryptanalysis of DES with a Reduced Number of Rounds, Sequences of Linear Factors in Block Ciphers, Advances in Cryptology, Proceedings of Crypto 85, pp. 192–211, 1985.
    Google Scholar

Download references

Author information

Authors and Affiliations

  1. Laboratorium ESAT, Katholieke Universiteit Leuven, Kardinaal Mercierlaan 94, B-3001, Heverlee, Belgium
    Joan Daemen, René Govaerts & Joos Vandewalle

Authors

  1. Joan Daemen
  2. René Govaerts
  3. Joos Vandewalle

Editor information

Editors and Affiliations

  1. Computer Science and Engineering Department and Center for Communication and Information Science, University of Nebraska, 68588-01115, Lincoln, NE, USA
    Douglas R. Stinson

Rights and permissions

© 1994 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Daemen, J., Govaerts, R., Vandewalle, J. (1994). Weak Keys for IDEA. In: Stinson, D.R. (eds) Advances in Cryptology — CRYPTO’ 93. CRYPTO 1993. Lecture Notes in Computer Science, vol 773. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-48329-2\_20

Download citation

Keywords

These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.

Publish with us