Camellia (cipher)
| General | |
|---|---|
| Designers | Mitsubishi, NTT |
| First published | 2000 |
| Derived from | E2, MISTY1 |
| Certification | CRYPTREC, NESSIE |
| Cipher detail | |
| Key sizes | 128, 192 or 256 bits |
| Block sizes | 128 bits |
| Structure | Feistel network |
| Rounds | 18 or 24 |
In cryptography, Camellia is a 128-bit block cipher jointly developed by Mitsubishi and NTT. The cipher has been approved for use by the ISO/IEC, the European Union's NESSIE project and the Japanese CRYPTREC project. The cipher has security levels and processing abilities comparable to the Advanced Encryption Standard.[1]
Camellia's block size is 16 bytes (128 bits), and can use 128-bit, 192-bit or 256-bit keys. The block cipher was designed to be suitable for both software and hardware implementations, from low-cost smart cards to high-speed network systems.[2]
Contents |
[edit] Design
Camellia is a Feistel cipher with either 18 rounds (when using 128-bit keys) or 24 rounds (when using 192 or 256-bit keys). Every six rounds, a logical transformation layer is applied: the so-called "FL-function" or its inverse. Camellia uses four 8 x 8-bit S-boxes with input and output affine transformations and logical operations. The cipher also uses input and output key whitening. The diffusion layer uses a linear transformation based on an MDS matrix with a branch number of 5.
[edit] Security analysis
|
|
This Security analysis may be too technical for most readers to understand. Please help improve this article to make it understandable to non-experts, without removing the technical details. The talk page may contain suggestions. (August 2010) |
Camellia is a block cipher which can be completely defined by minimal systems of multivariate polynomials.[vague][3] The Camellia (as well as AES) S-boxes can be described by a system of 23 quadratic equations in 80 terms.[4] The key schedule can be described by 1120 equations in 768 variables using 3328 linear and quadratic terms.[3] The entire block cipher can be described by 5104 equations in 2816 variables using 14592 linear and quadratic terms.[3] In total, 6224 equations in 3584 variables using 17920 linear and quadratic terms are required.[3] The number of free terms is 11696, which is approximately the same number as for AES. Theoretically, such properties might make it possible to break Camellia (and AES) using an algebraic attack, such as Extended Sparse Linearisation, in the future (provided that the attack becomes feasible). With today's technology, such an attack would take years to compute, and thus is not realistic.
[edit] Patent status
Camellia is patented and available under a royalty-free license.[5] This has allowed the Camellia cipher to become part of the OpenSSL Project, under an Open-source license, since November 2006.[6] It has also allowed it to become part of the Mozilla's NSS (Network Security Services) module.[7]
[edit] Adoption
Support for Camellia was added to the final release of Mozilla Firefox 3 in 2008.[7] Later in the same year, the FreeBSD Release Engineering Team announced that the cipher had also been included in the FreeBSD 6.4-RELEASE. Also, support for the Camellia cipher was added to the disk encryption storage class geli of FreeBSD by Yoshisato Yanagisawa. In September 2009, GNU Privacy Guard added support for Camellia in version 1.4.10.[8]
Moreover, various popular security libraries, such as Crypto++, GnuTLS, PolarSSL and OpenSSL also include support for Camellia.
[edit] See also
[edit] References
- ^ "Japan's First 128-bit Block Cipher 'Camellia' Approved as a New Standard Encryption Algorithm in the Internet". physorg.com. 2005. http://www.physorg.com/news5315.html. Retrieved 2010-08-12.
- ^ "Camellia Cipher Suites for TLS". RFC 4132. IETF. 2005. http://www.ietf.org/rfc/rfc4132.txt. Retrieved 2010-08-12.
- ^ a b c d Biryukov, De Cannière (2003), "Block ciphers and systems of quadratic equations", Lecture Notes in Computer Science, proceedings of FSE 2003 (Springer-Verlag): pp. 274–289, http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.95.349&rep=rep1&type=pdf
- ^ N. T. Courtois, J. Pieprzyk (2002), Cryptanalysis of block ciphers with overdefined systems of equations, Springer-Verlag, pp. 267–287, http://eprint.iacr.org/2002/044.pdf, retrieved 2010-08-13
- ^ "Announcement of Royalty-free Licenses for Essential Patents of NTT Encryption and Digital Signature Algorithms" (Press release). NTT. 2001-04-17. http://www.ntt.co.jp/news/news01e/0104/010417.html. Retrieved 2006-11-08.
- ^ "The Open Source Community OpenSSL Project Adopts the Next Generation International Standard Cipher "Camellia" Developed in Japan" (Press release). NTT. 2006-11-08. http://www.ntt.co.jp/news/news06e/0611/061108a.html. Retrieved 2008-02-29.
- ^ a b "Camellia cipher added to Firefox". Mozilla in Asia. Mozilla. July 30, 2009. http://blog.mozilla.com/gen/2007/07/30/camellia-cipher-added-to-firefox/.
- ^ "GnuPG 1.4.10 released". September 2, 2009. http://lists.gnupg.org/pipermail/gnupg-announce/2009q3/000291.html.
- Xin-jie ZHAO, Tao WANG, Yuan-yuan ZHENG (2009). "Cache Timing Attacks on Camellia Block Cipher". eprint. pp. 1–18. http://eprint.iacr.org/2009/354.pdf. Retrieved 2009-09-14.
- Xin-jie ZHAO, Tao WANG (2009). "An Improved Differential Fault Attack on Camellia". eprint. pp. 1–18. http://eprint.iacr.org/2009/585.pdf. Retrieved 2009-12-02.
- Xin-jie ZHAO, Tao WANG (2010). "Further Improved Differential Fault Attacks on Camellia by Exploring Fault Width and Depth". eprint. pp. 1–16. http://eprint.iacr.org/2010/026.pdf. Retrieved 2010-01-18.
[edit] External links
- Camellia's English home page
- Reference implementation and derived code
- RFC 3713 A Description of the Camellia Encryption Algorithm
- RFC 3657 Use of the Camellia Encryption Algorithm in Cryptographic Message Syntax (CMS)
- RFC 4312 The Camellia Cipher Algorithm and Its Use With IPsec
- RFC 4132 Addition of Camellia Cipher Suites to Transport Layer Security (TLS)
- RFC 5581 Certification of Camellia Cipher as IETF standard for OpenPGP
- Bug 382223: Add support for Camellia to PSM (Mozilla Firefox)
- FreeBSD System Manager's Manual: Add support for Camellia to geli (FreeBSD)
|
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||