Internal Symmetries and Linear Properties: Full-permutation Distinguishers and Improved Collisions on Gimli
نویسندگان
چکیده
$$\mathsf {Gimli}$$ is a family of cryptographic primitives (both hash function and an AEAD scheme) that has been selected for the second round NIST competition standardizing new lightweight designs. The candidate based on permutation , which was presented at CHES 2017. In this paper, we study security both constructions are it. We exploit slow diffusion in its internal symmetries to build, first time, distinguisher full complexity $$2^{64}$$ . also provide practical 23 out 24 rounds implemented. Next, give (full state) collision semi-free start attacks -Hash, reaching, respectively, up 12 18 rounds. On side, compute 8-round -Hash. quantum setting, these reach 2 more Finally, perform linear trails find permutation.
منابع مشابه
on the effect of linear & non-linear texts on students comprehension and recalling
چکیده ندارد.
15 صفحه اولGimli : A Cross-Platform Permutation
This paper presents Gimli, a 384-bit permutation designed to achieve high security with high performance across a broad range of platforms, including 64-bit Intel/AMD server CPUs, 64-bit and 32bit ARM smartphone CPUs, 32-bit ARM microcontrollers, 8-bit AVR microcontrollers, FPGAs, ASICs without side-channel protection, and ASICs with side-channel protection.
متن کاملImproved Linear Distinguishers for SNOW 2.0
In this paper we present new and more accurate estimates of the biases of the linear approximation of the FSM of the stream cipher SNOW 2.0. Based on improved bias estimates we also find a new linear distinguisher with bias 2−86.9 that is significantly stronger than the previously found ones by Watanabe et al. (2003) and makes it possible to distinguish the output keystream of SNOW 2.0 of lengt...
متن کاملImproved distinguishers for HC-128
HC-128 is an eSTREAM final portfolio stream cipher. Several authors have investigated its security and, in particular, distinguishing attacks have been considered. Still, no one has been able to provide a distinguisher stronger than the one presented by Wu in the original HC128 paper. In this paper we first argue that the keystream requirement in Wu’s original attack is underestimated by a fact...
متن کاملon semihypergroups and hypergroups
in this thesis, first the notion of weak mutual associativity (w.m.a.) and the necessary and sufficient condition for a $(l,gamma)$-associated hypersemigroup $(h, ast)$ derived from some family of $lesssim$-preordered semigroups to be a hypergroup, are given. second, by proving the fact that the concrete categories, semihypergroups and hypergroups have not free objects we will introduce t...
15 صفحه اولذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Journal of Cryptology
سال: 2021
ISSN: ['0933-2790', '1432-1378']
DOI: https://doi.org/10.1007/s00145-021-09413-z