2009
DOI: 10.1007/978-3-642-03317-9_1
|View full text |Cite
|
Sign up to set email alerts
|

Cube Testers and Key Recovery Attacks on Reduced-Round MD6 and Trivium

Abstract: Abstract. CRYPTO 2008 saw the introduction of the hash function MD6 and of cube attacks, a type of algebraic attack applicable to cryptographic functions having a low-degree algebraic normal form over GF(2). This paper applies cube attacks to reduced round MD6, finding the full 128-bit key of a 14-round MD6 with complexity 2 22 (which takes less than a minute on a single PC). This is the best key recovery attack announced so far for MD6. We then introduce a new class of attacks called cube testers, based on ef… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
138
0
1

Year Published

2013
2013
2022
2022

Publication Types

Select...
6
1

Relationship

1
6

Authors

Journals

citations
Cited by 128 publications
(139 citation statements)
references
References 17 publications
0
138
0
1
Order By: Relevance
“…For the sake of completeness we mention some distinguisher attacks based on cube testers in [27,6,35]. The best covers up to 961 rounds working in a reduced key space of 2 26 keys (out of 2 80 ).…”
Section: Related Workmentioning
confidence: 99%
“…For the sake of completeness we mention some distinguisher attacks based on cube testers in [27,6,35]. The best covers up to 961 rounds working in a reduced key space of 2 26 keys (out of 2 80 ).…”
Section: Related Workmentioning
confidence: 99%
“…Since its introduction, the cube attack was applied to many different cryptographic primitives such as [3,4,21]. Below we give a brief description of the cube attack, and refer the reader to [14] for more details.…”
Section: Cube Attacksmentioning
confidence: 99%
“…The notion of cube testers was introduced in [3], as an extension of the cube attack. Unlike standard cube attacks, cube testers aim at detecting a non-random behaviour (rather than performing key recovery), e.g., by observing that the cube sums are always equal to zero, regardless of the value of the secret key.…”
Section: Cube Testersmentioning
confidence: 99%
See 2 more Smart Citations