2017
DOI: 10.46586/tosc.v2017.i4.188-211
|View full text |Cite
|
Sign up to set email alerts
|

Shorter Linear Straight-Line Programs for MDS Matrices

Abstract: Recently a lot of attention is paid to the search for efficiently implementable MDS matrices for lightweight symmetric primitives. Most previous work concentrated on locally optimizing the multiplication with single matrix elements. Separate from this line of work, several heuristics were developed to find shortest linear straightline programs. Solving this problem actually corresponds to globally optimizing multiplications by matrices. In this work we combine those, so far largely independent lines of work. A… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
31
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 40 publications
(31 citation statements)
references
References 27 publications
0
31
0
Order By: Relevance
“…. Then the sw-xor of matrix M is 36, while the best previous result is 42 xor gates [14]. Then, we have the following conclusion.…”
Section: Mds Matrices With the Fewest Sequential Xor Count Based On Wordsmentioning
confidence: 71%
See 3 more Smart Citations
“…. Then the sw-xor of matrix M is 36, while the best previous result is 42 xor gates [14]. Then, we have the following conclusion.…”
Section: Mds Matrices With the Fewest Sequential Xor Count Based On Wordsmentioning
confidence: 71%
“…Finally, we find 10 classes of involutory MDS matrices with 36 sw-xor and present them in Table 8. Now, we take an example to compare our constructions with previous ones in [14,16].…”
Section: Mds Matrices With the Fewest Sequential Xor Count Based On Wordsmentioning
confidence: 99%
See 2 more Smart Citations
“…Table 2 ), but we were not able to reproduce these results. However, highly optimized, shallower circuits have been proposed in the hardware design literature such as [ 7 , 18 , 26 , 30 , 50 ]. Hence, we chose to use one of those and experiment with a recent design by Maximov [ 34 ].…”
Section: A Quantum Circuit For Aesmentioning
confidence: 99%