Key Recovery Attack on Py and Pypy with Chosen IVs

  title={Key Recovery Attack on Py and Pypy with Chosen IVs},
  author={Hongjun Wu and Bart Preneel},
In this paper we extend our previous attack to recover the key of Py and Pypy. If the IV size is at least ten bytes, the chosen IV attack can be applied to recover the key information of Py and Pypy. In general, ivsiveb− 9 bytes of the key can be recovered, where ivsizeb indicates the size of the IV in bytes. For example, for 256-bit key and 256-bit IV, the key is reduced to 72 bits with about 2 chosen IVs. For 128-bit key and 256-bit IV, the key can be recovered easily with about 2 chosen IVs. 

From This Paper

Topics from this paper.


Publications referenced by this paper.
Showing 1-4 of 4 references

Pypy: Another Version of Py.

E. Biham, J. Seberry
Available at http://www • 2006
View 10 Excerpts
Highly Influenced

Improved cryptanalysis of Py

IACR Cryptology ePrint Archive • 2006
View 2 Excerpts

Similar Papers

Loading similar papers…