2023
DOI: 10.1587/transfun.2022cip0013
|View full text |Cite
|
Sign up to set email alerts
|

Security Evaluation of Initialization Phases and Round Functions of Rocca and AEGIS

Abstract: Authenticated-Encryption with Associated-Data (AEAD) plays an important role in guaranteeing confidentiality, integrity, and authenticity in network communications. To meet the requirements of high-performance applications, several AEADs make use of AES New Instructions (AES-NI), which can conduct operations of AES encryption and decryption dramatically fast by hardware accelerations. At SAC 2013, Wu and Preneel proposed an AES-based AEAD scheme called AEGIS-128/128L/256, to achieve high-speed software impleme… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
4
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
2

Relationship

1
1

Authors

Journals

citations
Cited by 2 publications
(5 citation statements)
references
References 19 publications
0
4
0
Order By: Relevance
“…According to Section 3.2, Tiaoxin‐346 has a nonce input to T 6 [1], and T 6 [11] and T 6 [1] are only called at least 4 AES round functions in 15 rounds. Because the longest integral distinguisher of AES has been discovered up to 4 rounds [10], we consider that the distinguisher was discovered in 15 rounds that are full rounds.…”
Section: Discussionmentioning
confidence: 99%
See 3 more Smart Citations
“…According to Section 3.2, Tiaoxin‐346 has a nonce input to T 6 [1], and T 6 [11] and T 6 [1] are only called at least 4 AES round functions in 15 rounds. Because the longest integral distinguisher of AES has been discovered up to 4 rounds [10], we consider that the distinguisher was discovered in 15 rounds that are full rounds.…”
Section: Discussionmentioning
confidence: 99%
“…Regarding integral attacks, we present integral distinguishers on 6/6/7, 15, and 7 rounds of AEGIS-128/ 128L/256, Tiaoxin-346, and Rocca, respectively. Exploiting the full degree of freedom of nonce, these can improve 1 round of integral distinguishers on AEGIS-128L and Rocca from the results of Takeuchi et al [11], and the first result on integral properties of Tiaoxin-346 (Table 2). The encryption phase.…”
Section: Our Contributionmentioning
confidence: 95%
See 2 more Smart Citations
“…Takeuchi et al studied the optimality of the round function of Rocca [TSI23a]. See [TSI23b] for the security evaluation…”
Section: Related Workmentioning
confidence: 99%