Computing the Distribution of Differentials over the Non-linear Mapping χ

Security, Privacy, and Applied Cryptography Engineering: 11th International Conference, SPACE 2021, Kolkata, India, December 10–13, 2021, Proceedings(2021)

引用 0|浏览0
暂无评分
摘要
When choosing the non-linear layer in a symmetric design, the number of differentials with given differential probability (DP) gives information about how such non-linear layer may perform in the wide trail strategy. Namely, less differentials with high DP means less opportunity to form trails with high DP over multiple rounds. Multiple cryptographic primitives use the χ mapping as basis of their non-linear layer. Among them, Keccak- f , Ascon, Xoodoo, and Subterranean. In the first three, the χ mapping operates on groups of few bits (5 in Keccak- f and Ascon, and 3 in Xoodoo), while in Subterranean it operates on the full state, that is on 257 bits. In the former case, determining the number of differentials with given differential probability is an easy task, while the latter case is more involved. In this paper, we present a method to determine the number of differentials with given DP over χ operating on any number of bits.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要