2023
DOI: 10.1587/transfun.2021eap1158
|View full text |Cite
|
Sign up to set email alerts
|

On Optimality of the Round Function of Rocca

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

1
3
0

Year Published

2024
2024
2024
2024

Publication Types

Select...
2
1

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(4 citation statements)
references
References 9 publications
1
3
0
Order By: Relevance
“…Although we did not perform a dedicated search to reduce the number of registers used in rate-2 candidates, we note that PetitMac's round function (Figure 3) requires 6 registers in total, and can be implemented without any additional temporary register 8 . Therefore, this improves on the result of Nikolic [Nik17b, Appendix C], which does not find a rate-2 candidate with less than 8 registers; the candidates found may moreover require additional temporary registers in the implementation (see [TSI23] for similar concerns on Rocca). 3 1 A message is added every other round.…”
Section: Results Of the Searchsupporting
confidence: 69%
See 2 more Smart Citations
“…Although we did not perform a dedicated search to reduce the number of registers used in rate-2 candidates, we note that PetitMac's round function (Figure 3) requires 6 registers in total, and can be implemented without any additional temporary register 8 . Therefore, this improves on the result of Nikolic [Nik17b, Appendix C], which does not find a rate-2 candidate with less than 8 registers; the candidates found may moreover require additional temporary registers in the implementation (see [TSI23] for similar concerns on Rocca). 3 1 A message is added every other round.…”
Section: Results Of the Searchsupporting
confidence: 69%
“…This is the direction taken by the Authenticated Encryption (AE) algorithm Rocca [SLN + 21, SLN + 22] and its updated version Rocca-S [NFI24], currently the fastest AE on AES-NI platforms and under submission at IETF. Recently, the round function framework of Rocca has been further analysed in a work that presents optimal round function candidates (in terms of speed) within the framework [TSI23].…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…Shiraya et al analyzed distinguishing attacks on the initialization phase and keystream [STSI23]. Takeuchi et al studied the optimality of the round function of Rocca [TSI23a]. See [TSI23b] for the security evaluation…”
Section: Related Workmentioning
confidence: 99%