Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks
Offered By: TheIACR via YouTube
Course Description
Overview
Syllabus
Intro
Overview Cube attack[DS09] : Variant of higher-order differential attacks.
Results from our new algorithm Degeneration results
Stream ciphers
History of cube attacks 1st generation [DS09]
What assumptions are required in the 2nd gen?NTT [TIHM17] used the bit-based division property.
Idea of 3rd gen. cube attack • The preliminary idea was introduced in WHGZS19 .
Path search based on division trail Goal is to check if f(x) has the monomial x or not.
Three-subset division property • We need to use two different propagations.
MILP-unfriendly property Three-subset division property is unfriendly with MILP.
Three-subset division property w/o unknown NTT
The new modeling
Cube attack against Trivium 839-round key recovery attack WHTLIM 18 .
Summary of applications
Taught by
TheIACR
Related Courses
Криптографические методы защиты информацииNational Research Nuclear University MEPhI via edX Foundations of Cryptography
NPTEL via Swayam Symmetric Cryptography Essential Training
LinkedIn Learning Foundations of Cryptography
NPTEL via YouTube Cryptography and Network Security
NPTEL via YouTube