Some New Observations on the SMS4 Block Cipher in the Chinese WAPI Standard

Published: 01 Jan 2009, Last Modified: 11 Feb 2025ISPEC 2009EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: SMS4 is a 128-bit block cipher used in the WAPI standard in wireless networks in China. The cipher has attracted much attention in the past two years. This paper consists of two parts. The first part is on the design of the linear diffusion layer L of SMS4. Some new observations on L are present, which open out the design rationales of L and such class functions to a great extent. The second part is on the differential attack against SMS4. A class of 18-round differential characteristics with a higher probability is given. Then a simple differential attack on 22-round SMS4 is present, which is an improvement of the previous work, thus our attack becomes the best known one on SMS4. Furthermore, we make a remark on the construction of differential characteristics of SMS4.
Loading