IACR Transactions on Symmetric Cryptology 2017
DOI: 10.13154/tosc.v2017.i4.188-211
|View full text |Cite
|
Sign up to set email alerts
|

Shorter Linear Straight-Line Programs for MDS Matrices. Yet another XOR Count Paper

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2

Citation Types

0
2
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
6

Relationship

0
6

Authors

Journals

citations
Cited by 12 publications
(2 citation statements)
references
References 0 publications
0
2
0
Order By: Relevance
“…Their combination allows to prove that the number of active S-boxes in any 4-round trail is 25, or in general, the square of the branch number [12]. In the context of lightweight cryptography, there has been ample research about constructing MDS matrices with low gate cost, see [2,17,[23][24][25]27,33,35]. While most research is about 4 × 4 matrices, the first MixColumn-like MDS matrices for use in cryptographic round functions were 8 × 8, introduced in the block cipher SHARK [32].…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…Their combination allows to prove that the number of active S-boxes in any 4-round trail is 25, or in general, the square of the branch number [12]. In the context of lightweight cryptography, there has been ample research about constructing MDS matrices with low gate cost, see [2,17,[23][24][25]27,33,35]. While most research is about 4 × 4 matrices, the first MixColumn-like MDS matrices for use in cryptographic round functions were 8 × 8, introduced in the block cipher SHARK [32].…”
Section: Introductionmentioning
confidence: 99%
“…While most research is about 4 × 4 matrices, the first MixColumn-like MDS matrices for use in cryptographic round functions were 8 × 8, introduced in the block cipher SHARK [32]. Later 8×8 MDS matrices were used in the compression function of hash functions such as Whirlpool [1] and there has also been research on reducing the gate cost of such mappings [23]. Constructions that combine 8 × 8 MDS matrices with an appropriate ShiftRows mapping have at least 9 2 = 81 active S-boxes in any 4-round trail.…”
Section: Introductionmentioning
confidence: 99%