Bounds in Shallows and in Miseries
نویسندگان
چکیده
Proving bounds on the expected differential probability (EDP) of a characteristic over all keys has been a popular technique of arguing security for both block ciphers and hash functions. In fact, to a large extent, it was the clear formulation and elegant deployment of this very principle that helped Rijndael win the AES competition. Moreover, most SHA-3 finalists have come with explicit upper bounds on the EDP of a characteristic as a major part of their design rationale. However, despite the pervasiveness of this design approach, there is no understanding of what such bounds actually mean for the security of a primitive once a key is fixed — an essential security question in practice. In this paper, we aim to bridge this fundamental gap. Our main result is a quantitative connection between a bound on the EDP of differential characteristics and the highest number of input pairs that actually satisfy a characteristic for a fixed key. This is particularly important for the design of permutation-based hash functions such as sponge functions, where the EDP value itself is not informative for the absence of rekeying. We apply our theoretical result to revisit the security arguments of some prominent recent block ciphers and hash functions. For most of those, we have good news: a characteristic is followed by a small number of pairs only. For Keccak, though, currently much more rounds would be needed for our technique to guarantee any reasonable maximum number of pairs. Thus, our work — for the first time — sheds light on the fixed-key differential behaviour of block ciphers in general and substitution-permutation networks in particular which has been a long-standing fundamental problem in symmetric-key cryptography.
منابع مشابه
The gender encountering situations in the university and their miseries
This article is about studying girl students’ gender miseries in the Iranian university. The population of the university is the only mixed sex population in an official and governmental space in which the population is highly by cultural circulation and variations. Due to this fact, the gender encountering happens a lot through the everyday relations of the university. The gender encountering ...
متن کاملGolden opportunities: A horizon scan to expand sandy beach ecology
Robust ecological paradigms and theories should, ideally, hold across several ecosystems. Yet, limited testing of generalities has occurred in some habitats despite these habitats offering unique features to make them good model systems for experiments. We contend this is the case for the ocean-exposed sandy beaches. Beaches have several distinctive traits, including extreme malleability of hab...
متن کاملImpacts of Premium Bounds on the Operation of Put Option and Day-ahead Electricity Markets
In this paper, the impacts of premium bounds of put option contracts on the operation of put option and day-ahead electricity markets are studied. To this end, first a comprehensive equilibrium model for a joint put option and day-ahead markets is presented. Interaction between put option and day-ahead markets, uncertainty in fuel price, impact of premium bounds, and elasticity of con...
متن کاملEfficiency Evaluation and Ranking DMUs in the Presence of Interval Data with Stochastic Bounds
On account of the existence of uncertainty, DEA occasionally faces the situation of imprecise data, especially when a set of DMUs include missing data, ordinal data, interval data, stochastic data, or fuzzy data. Therefore, how to evaluate the efficiency of a set of DMUs in interval environments is a problem worth studying. In this paper, we discussed the new method for evaluation and ranking i...
متن کاملStrong exponent bounds for the local Rankin-Selberg convolution
Let $F$ be a non-Archimedean locally compact field. Let $sigma$ and $tau$ be finite-dimensional representations of the Weil-Deligne group of $F$. We give strong upper and lower bounds for the Artin and Swan exponents of $sigmaotimestau$ in terms of those of $sigma$ and $tau$. We give a different lower bound in terms of $sigmaotimeschecksigma$ and $tauotimeschecktau$. Using the Langlands...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2013 شماره
صفحات -
تاریخ انتشار 2013