Summary: | In this paper, we present a new structure-recovery cryptanalysis against 16-round Skipjack-like structure in which all the inner transformations are unknown. Our attack is divided into three phases. In the first phase, we use yoyo game to recover the outermost round functions. In the second phase, we use integral attack to achieve the round functions in round 2/3/4/13/14/15. A series of equations based on integral distinguishers is established to recover these inner transformations. However, effective integral distinguishers cannot be constructed for shorter rounds. For this reason, we propose a guess and determine attack to recover the residue round functions in the third phase. For n-bit Skipjack-like cipher, our attack can be executed within time complexity O(2<sup>2.81×n/4</sup>) and data complexity O(2<sup>n/2</sup>), and thus can lead to a practical attack against 16-round Skipjack cipher.
|