2016
DOI: 10.1007/978-3-662-52993-5_19
|View full text |Cite
|
Sign up to set email alerts
|

Algebraic Insights into the Secret Feistel Network

Abstract: Abstract. We introduce the high-degree indicator matrix (HDIM), an object closely related with both the linear approximation table and the algebraic normal form (ANF) of a permutation. We show that the HDIM of a Feistel Network contains very specific patterns depending on the degree of the Feistel functions, the number of rounds and whether the Feistel functions are 1-to-1 or not. We exploit these patterns to distinguish Feistel Networks, even if the Feistel Network is whitened using unknown affine layers. We … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
6
0

Year Published

2016
2016
2023
2023

Publication Types

Select...
7
1

Relationship

3
5

Authors

Journals

citations
Cited by 10 publications
(7 citation statements)
references
References 17 publications
(23 reference statements)
1
6
0
Order By: Relevance
“…We deduce from Corollary 1 that a good rule of thumb to estimate the number of SPN rounds necessary to achieve full degree is to use 2 × ⌊log −1 ( )⌋ rounds. Interestingly, this result is very similar to what is stated in Theorem 1 of [PU16]. Indeed, in this paper, the existence of integral distinguishers for about 2 log ( ) rounds of Feistel Network are derived, where is the degree of the Feistel function.…”
Section: A Bound On the Algebraic Degree Of A Spnsupporting
confidence: 83%
See 1 more Smart Citation
“…We deduce from Corollary 1 that a good rule of thumb to estimate the number of SPN rounds necessary to achieve full degree is to use 2 × ⌊log −1 ( )⌋ rounds. Interestingly, this result is very similar to what is stated in Theorem 1 of [PU16]. Indeed, in this paper, the existence of integral distinguishers for about 2 log ( ) rounds of Feistel Network are derived, where is the degree of the Feistel function.…”
Section: A Bound On the Algebraic Degree Of A Spnsupporting
confidence: 83%
“…Proof. We consider the high-degree indicator matrix (hdim) of , as introduced in [PU16]. It is defined as a × binary matrix where the coefficient at line and column is equal to 1 if and only if the monomial ∏︀…”
Section: Lemma 1 Let Be An -Bit Function and ( ) Be The Number Of mentioning
confidence: 99%
“…We show three works related to integral distinguisher, division property [4], bit-based division property [6] and HDIM [10]. These three works have similarity with our method, since they use the ANF and estimate algebraic degree to construct integral distinguisher.…”
Section: Related Workmentioning
confidence: 83%
“…Aside from division property, Perrin et al proposed high-degree indicator matrix (HDIM) which can be used to search for integral distinguisher [10] in FSE2016. This is experimental method whose time and memory complexity increases in exponential order with the block length.…”
Section: Introductionmentioning
confidence: 99%
“…The distribution of differential probabilities of fixed or random S-box is sufficient to find S-box with the best security parameters values (which is quite obvious usage). But with this information one can also evaluate security of ciphers with random or pseudo-random S-boxes or even restore a hidden internal algebraic structure of cryptographic mappings (like in [5,6]). Differentials with respect to XOR operation are widely used in differential cryptanalysis; O'Connor found exact combinatorial formulas for distribution of such differentials for random S-box [7], but these formulas are very ponderous, thus they are poorly applicable in practice.…”
Section: Introductionmentioning
confidence: 99%