1. School of Mathematics and Physics, University of Science and Technology Beijing, Beijing 100083, China;
2. Department of Basic Courses, University of Science and Technology Beijing, Beijing 102100, China
Abstract��In order to research the ability of Zodiac algorithm against the collision attack, two 8-round and 9-round distinguishers of Zodiac algorithm based on an equivalent structure of it were proposed. Firstly, collision attacks were applied to the algorithm from 12-round to 16-round by adding proper rounds before or after the 9-round distinguishers. The data complexities were 215, 231.2, 231.5, 231.7and 263.9, and the time complexities were 233.8, 249.9, 275.1, 2108and 2140.1, respectively. Then the 8-round distinguishers were applied to the full-round algorithm. The data complexity and time complexity were 260.6 and 2173.9, respectively. These results show that both full-round Zodiac-192 and full-round Zodiac-256 are not immune to collision attack.