Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks
Offered By: TheIACR via YouTube
Course Description
Overview
Syllabus
Intro
Overview Cube attack[DS09] : Variant of higher-order differential attacks.
Results from our new algorithm Degeneration results
Stream ciphers
History of cube attacks 1st generation [DS09]
What assumptions are required in the 2nd gen?NTT [TIHM17] used the bit-based division property.
Idea of 3rd gen. cube attack • The preliminary idea was introduced in WHGZS19 .
Path search based on division trail Goal is to check if f(x) has the monomial x or not.
Three-subset division property • We need to use two different propagations.
MILP-unfriendly property Three-subset division property is unfriendly with MILP.
Three-subset division property w/o unknown NTT
The new modeling
Cube attack against Trivium 839-round key recovery attack WHTLIM 18 .
Summary of applications
Taught by
TheIACR
Related Courses
Internetwork SecurityIndian Institute of Technology, Kharagpur via Swayam Classical Cryptosystems and Core Concepts
University of Colorado System via Coursera Cryptography and Information Theory
University of Colorado System via Coursera Cryptography And Network Security
Indian Institute of Technology, Kharagpur via Swayam An Introduction to Cryptography
Coventry University via FutureLearn