2017
DOI: 10.46586/tosc.v2017.i1.240-258
|View full text |Cite
|
Sign up to set email alerts
|

SymSum: Symmetric-Sum Distinguishers Against Round Reduced SHA3

Abstract: In this work we show the existence of special sets of inputs for which the sum of the images under SHA3 exhibits a symmetric property. We develop an analytical framework which accounts for the existence of these sets. The framework constitutes identification of a generic property of iterated SPN based functions pertaining to the round-constant addition and combining it with the notion of m−fold vectorial derivatives for differentiation over specially selected subspaces. Based on this we propose a new distingui… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2018
2018
2024
2024

Publication Types

Select...
4
1

Relationship

0
5

Authors

Journals

citations
Cited by 8 publications
(1 citation statement)
references
References 10 publications
0
1
0
Order By: Relevance
“…They allow producing a set of input and of output values that both sum to zero, and this in about half the time it would be needed on a random permutation with only black-box access. These structural distinguishers are of nice theoretical interest, but they do not pose a threat as they do not extend to distringuishers on sponge functions that use Keccak-p[1600, n r ], see, e.g., [35].…”
Section: Choice Of the Number Of Roundsmentioning
confidence: 99%
“…They allow producing a set of input and of output values that both sum to zero, and this in about half the time it would be needed on a random permutation with only black-box access. These structural distinguishers are of nice theoretical interest, but they do not pose a threat as they do not extend to distringuishers on sponge functions that use Keccak-p[1600, n r ], see, e.g., [35].…”
Section: Choice Of the Number Of Roundsmentioning
confidence: 99%