Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks
Offered By: TheIACR via YouTube
Course Description
Overview
Syllabus
Intro
Overview Cube attack[DS09] : Variant of higher-order differential attacks.
Results from our new algorithm Degeneration results
Stream ciphers
History of cube attacks 1st generation [DS09]
What assumptions are required in the 2nd gen?NTT [TIHM17] used the bit-based division property.
Idea of 3rd gen. cube attack • The preliminary idea was introduced in WHGZS19 .
Path search based on division trail Goal is to check if f(x) has the monomial x or not.
Three-subset division property • We need to use two different propagations.
MILP-unfriendly property Three-subset division property is unfriendly with MILP.
Three-subset division property w/o unknown NTT
The new modeling
Cube attack against Trivium 839-round key recovery attack WHTLIM 18 .
Summary of applications
Taught by
TheIACR
Related Courses
Applied CryptographyUniversity of Virginia via Udacity Cryptography II
Stanford University via Coursera Coding the Matrix: Linear Algebra through Computer Science Applications
Brown University via Coursera Cryptography I
Stanford University via Coursera Unpredictable? Randomness, Chance and Free Will
National University of Singapore via Coursera