Breaking HALFLOOP-24
2022 (English)In: IACR Transactions on Symmetric Cryptology, ISSN 2519-173X, Vol. 2022, no 3, p. 217-238Article in journal (Refereed) Published
Abstract [en]
HALFLOOP-24 is a tweakable block cipher that is used to protect automatic link establishment messages in high frequency radio, a technology commonly used by government agencies and industries that need highly robust long-distance communications. We present the first public cryptanalysis of HALFLOOP-24 and show that HALFLOOP-24, despite its key size of 128 bits, is far from providing 128 bit security. More precisely, we give attacks for ciphertext-only, known-plaintext, chosen-plaintext and chosen-ciphertext scenarios. In terms of their complexities, most of them can be considered practical. However, in the real world, the amount of available data is too low for our attacks to work. Our strongest attack, a boomerang key-recovery, finds the first round key with less than 210 encryption and decryption queries. In conclusion, we strongly advise against using HALFLOOP-24.
Place, publisher, year, edition, pages
2022. Vol. 2022, no 3, p. 217-238
Keywords [en]
HF Radio, ALE, HALFLOOP, Boomerang
National Category
Other Mathematics
Research subject
Systems science for defence and security
Identifiers
URN: urn:nbn:se:fhs:diva-11065DOI: 10.46586/tosc.v2022.i3.217-238OAI: oai:DiVA.org:fhs-11065DiVA, id: diva2:1695170
Conference
Fast Software Encryption (FSE) 2023, Beijing, China, March 20-24, 2023
2022-09-132022-09-132022-09-26Bibliographically approved