Internal Symmetries and Linear Properties: Full-permutation Distinguishers and Improved Collisions on Gimli

نویسندگان

چکیده

$$\mathsf {Gimli}$$ is a family of cryptographic primitives (both hash function and an AEAD scheme) that has been selected for the second round NIST competition standardizing new lightweight designs. The candidate based on permutation , which was presented at CHES 2017. In this paper, we study security both constructions are it. We exploit slow diffusion in its internal symmetries to build, first time, distinguisher full complexity $$2^{64}$$ . also provide practical 23 out 24 rounds implemented. Next, give (full state) collision semi-free start attacks -Hash, reaching, respectively, up 12 18 rounds. On side, compute 8-round -Hash. quantum setting, these reach 2 more Finally, perform linear trails find permutation.

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Gimli : A Cross-Platform Permutation

This paper presents Gimli, a 384-bit permutation designed to achieve high security with high performance across a broad range of platforms, including 64-bit Intel/AMD server CPUs, 64-bit and 32bit ARM smartphone CPUs, 32-bit ARM microcontrollers, 8-bit AVR microcontrollers, FPGAs, ASICs without side-channel protection, and ASICs with side-channel protection.

متن کامل

Improved Linear Distinguishers for SNOW 2.0

In this paper we present new and more accurate estimates of the biases of the linear approximation of the FSM of the stream cipher SNOW 2.0. Based on improved bias estimates we also find a new linear distinguisher with bias 2−86.9 that is significantly stronger than the previously found ones by Watanabe et al. (2003) and makes it possible to distinguish the output keystream of SNOW 2.0 of lengt...

متن کامل

Improved distinguishers for HC-128

HC-128 is an eSTREAM final portfolio stream cipher. Several authors have investigated its security and, in particular, distinguishing attacks have been considered. Still, no one has been able to provide a distinguisher stronger than the one presented by Wu in the original HC128 paper. In this paper we first argue that the keystream requirement in Wu’s original attack is underestimated by a fact...

متن کامل

on semihypergroups and hypergroups

in this thesis, first the notion of weak mutual associativity (w.m.a.) and the necessary and sufficient condition for a $(l,gamma)$-associated hypersemigroup $(h, ast)$ derived from some family of $lesssim$-preordered semigroups to be a hypergroup, are given. second, by proving the fact that the concrete categories, semihypergroups and hypergroups have not free objects we will introduce t...

15 صفحه اول

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Journal of Cryptology

سال: 2021

ISSN: ['0933-2790', '1432-1378']

DOI: https://doi.org/10.1007/s00145-021-09413-z