Higher-Order Differential Properties of Keccak and Luffa

Higher-Order Differential Properties of Keccak and Luffa
复制标题

DOI:
10.1007/978-3-642-21702-9_15
复制
发表时间:
2011-02
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Christina Boura;A. Canteaut;C. Cannière
Christina Boura;A. Canteaut;C. Cannière
中科院分区:
其他
文献类型:
--
作者:
Christina Boura;A. Canteaut;C. Cannière

文献摘要

被引文献

相似文献

在这篇文章中,我们在全Keccak-f置换、Luffav1散列函数和Luffav2算法的分量中证明了高阶微分和零和性质。这些结构性质依赖于迭代排列次数的一个新界,其中的非线性层由多个平衡Sbox的并行应用组成。这些技术为完整的Keccak-f置换产生了大小为21575的零和分割,并对Luffahash家族进行了几次观测。我们首先证明了应用于一块消息的Luffav1是255个变量的函数,其次数最多为251。这一观察结果导致了全Luffav1散列函数的高阶微分辨别器的构造,类似于Watanabeet等人在简化版本上提出的。我们证明了在Luffav2压缩函数中可以使用类似的技术来寻找全零的高阶微分,但是额外的空白轮破坏了散列函数中的这一性质。
In this paper, we identify higher-order differential and zero-sum properties in the fullKeccak-fpermutation, in theLuffav1 hash function and in components of theLuffav2 algorithm. These structural properties rely on a new bound on the degree of iterated permutations with a nonlinear layer composed of parallel applications of a number of balanced Sboxes. These techniques yield zero-sum partitions of size 21575for the fullKeccak-fpermutation and several observations on theLuffahash family. We first show thatLuffav1 applied to one-block messages is a function of 255 variables with degree at most 251. This observation leads to the construction of a higher-order differential distinguisher for the fullLuffav1 hash function, similar to the one presented by Watanabeet al.on a reduced version. We show that similar techniques can be used to find all-zero higher-order differentials in theLuffav2 compression function, but the additional blank round destroys this property in the hash function.