<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shabal</title>
	<atom:link href="http://www.shabal.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.shabal.com</link>
	<description>A submission to NIST&#039;s Cryptographic Hash Algorithm Competition</description>
	<lastBuildDate>Fri, 30 Jul 2010 12:49:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Internal Distinguishers in Indiﬀerentiable Hashing: The Shabal Case</title>
		<link>http://www.shabal.com/?p=158</link>
		<comments>http://www.shabal.com/?p=158#comments</comments>
		<pubDate>Wed, 28 Jul 2010 13:08:50 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Papers]]></category>
		<category><![CDATA[Shabal]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=158</guid>
		<description><![CDATA[We show the ﬁrst indiﬀerentiability proof of a hash construction C F which does not make the assumption that the inner primitive F is ideal, but allows the existence (up to certain bounds that we explicit) of statistical distinguishers on F. Our hash construction is a general domain extender that generalizes both Chop-MD and Shabal [...]]]></description>
			<content:encoded><![CDATA[<p>We show the ﬁrst indiﬀerentiability proof of a hash construction <em>C <sup>F</sup></em> which does not make the assumption that the inner primitive <em>F</em> is ideal, but allows the existence (up to certain bounds that we explicit) of statistical distinguishers on <em>F</em>. <span id="more-158"></span>Our hash construction is a general domain extender that generalizes both Chop-MD and Shabal and we prove that this general mode of operation is indiﬀerentiable from a random oracle by providing tight security bounds when the inner primitive <em>F</em> is either an ideal compression function or a keyed permutation. Our proof provides the tightest possible security bounds on Chop-MD and even improves the original indiﬀerentiability proof of Shabal. We then extend our results to the case where <em>F</em> is not assumed ideal anymore, but presents some (possibly strong) form of statistical bias in its input-output behavior. Our results allow us to derive new indiﬀerentiability bounds for Shabal and show that the series of recently found (order-1, diﬀerential or rotational) distinguishers on its internal keyed permutation leave fully intact its indiﬀerentiability properties.</p>
<p><strong>Authors:</strong> Emmanuel Bresson, Anne Canteaut, Thomas Fuhr, Thomas Icart, María Naya-Plasencia, Pascal Paillier, Jean-René Reinhard, Marion Videau</p>
<p><strong>Note:</strong> This work was partially supported by the French Agence Nationale de la Recherche through the SAPHIR2 project under Contract ANR-08-VERS-014.</p>
<p><strong>Download: </strong></p>
<p><strong> </strong><a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=Internal_Distinguishers_in_Indifferentiable_Hashing_The_Shabal_Case.pdf" title="VersionV1.0 downloaded 42 times" >Internall Distinguishers in Indifferentiable Hashing: The Shabal Case (42)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=158</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unfolding Method for Shabal on Virtex-5 FPGAs: Concrete Results</title>
		<link>http://www.shabal.com/?p=170</link>
		<comments>http://www.shabal.com/?p=170#comments</comments>
		<pubDate>Wed, 28 Jul 2010 13:06:50 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Implementations]]></category>
		<category><![CDATA[Papers]]></category>
		<category><![CDATA[Shabal]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=170</guid>
		<description><![CDATA[In this paper, we focus on an optimized implementation of the Shabal candidate. We improve the state-of-the-art using the unfolding method. This transformation leads to unroll a part of the Shabal core. More precisely, our design can produce a throughput over 3 Gbps on Virtex-5 FPGAs, with a reasonable area usage. Authors: Julien Francq and [...]]]></description>
			<content:encoded><![CDATA[<p>In this paper, we focus on an optimized implementation of the Shabal  candidate.  We improve the state-of-the-art using the unfolding method.<span id="more-170"></span> This transformation leads to unroll a part of the Shabal core.  More precisely, our design can produce a throughput over 3 Gbps on  Virtex-5 FPGAs, with a reasonable area usage.</p>
<p><strong>Authors:</strong> Julien Francq and Céline Thuillet</p>
<p><strong>Note:</strong> This  work  was partially  supported  by  the French  Agence Nationale de la Recherche through the SAPHIR2 project under Contract ANR-08-VERS-014.</p>
<p><strong>Download PDF:</strong> <a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=Unfolding-Method-for-Shabal-on-Virtex-5-FPGAs.pdf" title="Version1.0 downloaded 31 times" >Unfolding Method for Shabal on Virtex-5 FPGAs:  Concrete Results (31)</a></p>
<p><a href="http://www.shabal.com/?page_id=38&amp;did=13" target="_blank"><strong>Download implementations (529Mo)</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=170</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>High-Speed Implementation of the SHA-3 Candidate Shabal</title>
		<link>http://www.shabal.com/?p=165</link>
		<comments>http://www.shabal.com/?p=165#comments</comments>
		<pubDate>Wed, 28 Jul 2010 12:27:24 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Implementations]]></category>
		<category><![CDATA[Shabal]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=165</guid>
		<description><![CDATA[The presentation of Julien Francq and Céline Thuillet, &#8220;High-Speed Implementation of the SHA-3 Candidate Shabal&#8221; at CryptArchi 2010 is now available in the Download section. Download:]]></description>
			<content:encoded><![CDATA[<p>The presentation of Julien Francq and Céline Thuillet, &#8220;High-Speed Implementation of the SHA-3 Candidate Shabal&#8221; at <a href="http://labh-curien.univ-st-etienne.fr/cryptarchi/index.html" target="_blank">CryptArchi 2010</a> is now available in the Download section.<span id="more-165"></span></p>
<p><strong>Download: </strong></p>
<p><strong> </strong><a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=High-Speed-Implementation-of-the-SHA-3-Candidate-Shabal.pdf" title="Version1.0 downloaded 44 times" >High-Speed Implementation of the SHA-3 Candidate Shabal (44)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=165</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The list of the accepted papers for the Second SHA-3 Candidate Conference is now available</title>
		<link>http://www.shabal.com/?p=153</link>
		<comments>http://www.shabal.com/?p=153#comments</comments>
		<pubDate>Thu, 01 Jul 2010 09:32:42 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Papers]]></category>
		<category><![CDATA[Shabal]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=153</guid>
		<description><![CDATA[Two papers are about Shabal : Internal Distinguishers in Indifferentiable Hashing:  The Shabal Case Unfolding Method for Shabal on Virtex-5 FPGAs: Concrete Results The list of accepted papers is available at http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/Aug2010/documents/AcceptedPapersListing_SHA3_2010.pdf]]></description>
			<content:encoded><![CDATA[<p>Two papers are about Shabal :<span id="more-153"></span></p>
<ul>
<li>Internal Distinguishers in Indifferentiable Hashing:  The Shabal Case</li>
<li>Unfolding Method for Shabal on Virtex-5 FPGAs: Concrete Results</li>
</ul>
<p>The list of accepted papers is available at</p>
<p><a href="http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/Aug2010/documents/AcceptedPapersListing_SHA3_2010.pdf">http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/Aug2010/documents/AcceptedPapersListing_SHA3_2010.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=153</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSE2-enhanced parallel implementations of the Shabal hash functions</title>
		<link>http://www.shabal.com/?p=140</link>
		<comments>http://www.shabal.com/?p=140#comments</comments>
		<pubDate>Mon, 17 May 2010 12:54:17 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Implementations]]></category>
		<category><![CDATA[Shabal]]></category>
		<category><![CDATA[parallel]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=140</guid>
		<description><![CDATA[This SSE2-enhanced parallel implementations of the Shabal hash functions runs up to four parallel instances of Shabal (on four input data messages of identical length). This code was benched on an Intel x86 Core2 Q6600 system, clocked at 2.4 GHz and running Linux. The compiler is Intel C/C++ compiler version 11.1. Achieved speed (for long [...]]]></description>
			<content:encoded><![CDATA[<p>This<strong> SSE2-enhanced parallel implementations of the Shabal hash functions</strong> runs up to four parallel instances of Shabal (on four input data messages of identical length).<span id="more-140"></span></p>
<p>This code was benched on an Intel x86 Core2 Q6600 system, clocked at 2.4 GHz and running Linux. The compiler is Intel C/C++ compiler version 11.1. Achieved speed (for long messages) is <strong>631 MB/s</strong> (in 32-bit mode; 621 MB/s in 64-bit mode); this is the cumulative bandwidth of the four parallel instances (each instance is hashed with a bandwidth of about 158 MB/s). All of this is on a single CPU core.</p>
<p>See the mshabal.h header file for documentation on the API. The code itself should compile properly with GCC, the Intel C/C++ compiler, and Microsoft Visual C (this was tested with GCC 4.4.1 and Visual C 2005).</p>
<p>Download: <a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=multi-shabal.zip" title="Version1.0 downloaded 78 times" >SSE2-enhanced parallel implementations of the Shabal hash functions (78)</a></p>
<p>(c) 2010 SAPHIR project. This software is provided &#8216;as-is&#8217;, without any epxress or implied warranty. In no event will the authors be held liable for any damages arising from the use of this software.</p>
<p>Permission is granted to anyone to use this software for any purpose, including commercial applications, and to alter it and redistribute it freely, subject to no restriction.</p>
<p>Technical remarks and questions can be addressed to:<br />
&lt;thomas.pornin at cryptolog.com&gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=140</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;A Low-Area yet Performant FPGA Implementation of Shabal&#8221;</title>
		<link>http://www.shabal.com/?p=134</link>
		<comments>http://www.shabal.com/?p=134#comments</comments>
		<pubDate>Mon, 17 May 2010 12:40:36 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Implementations]]></category>
		<category><![CDATA[Shabal]]></category>
		<category><![CDATA[FPGA]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=134</guid>
		<description><![CDATA[A new paper on FPGA implementation of Shabal is available on ePrint. The authors are Jérémie Detrey, Pierrick Gaudry, and Karim Khalfallah. Abstract. In this paper, we present an efficient FPGA implementation of the SHA-3 hash function candidate Shabal. Targeted at the recent Xilinx Virtex-5 FPGA family, our design achieves a relatively high throughput of [...]]]></description>
			<content:encoded><![CDATA[<p>A new paper on FPGA implementation of Shabal is available on ePrint. The authors are Jérémie Detrey, Pierrick Gaudry, and Karim Khalfallah.</p>
<p style="padding-left: 30px;"><strong>Abstract.</strong> In this paper, we present an efficient FPGA implementation of the SHA-3 hash function candidate Shabal.<span id="more-134"></span> Targeted at the recent Xilinx Virtex-5 FPGA family, our design achieves a relatively high throughput of 2 Gbit/s at a cost of only 153 slices, yielding a throughput-vs.-area ratio of 13.4 Mbit/s per slice. Our work can also be ported to Xilinx Spartan-3 FPGAs, on which it supports a throughput of 800 Mbit/s for only 499 slices, or equivalently 1.6 Mbit/s per slice.<br />
According to the SHA-3 Zoo website, this work is among the smallest reported FPGA implementations of SHA-3 candidates, and ranks first in terms of throughput per area.</p>
<p style="padding-left: 30px;">
<p><a href="http://eprint.iacr.org/2010/292.pdf" target="_blank">PDF version</a> available on ePrint: <a href="http://eprint.iacr.org/2010/292" target="_blank">http://eprint.iacr.org/2010/292</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=134</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A compact implementation of Shabal</title>
		<link>http://www.shabal.com/?p=108</link>
		<comments>http://www.shabal.com/?p=108#comments</comments>
		<pubDate>Thu, 06 May 2010 11:25:55 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Implementations]]></category>
		<category><![CDATA[Shabal]]></category>
		<category><![CDATA[C]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=108</guid>
		<description><![CDATA[A new very small implementation of the Shabal hash function in language  C is available in the Donwload Section. For instance, when compiled with GCC-4.4.1 on an Intel x86 Linux system (32-bit mode), with the &#8220;-Os -fomit-frame-pointer&#8221; flags, the footprint of Shabal is 698 bytes. Yet it still hash data with a bandwidth of 109 [...]]]></description>
			<content:encoded><![CDATA[<p>A new very small implementation of the Shabal hash function in language  C is available in the <a href="http://www.shabal.com/?page_id=38" target="_blank">Donwload Section</a>.</p>
<p><span id="more-108"></span></p>
<a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=shabal-small_update.zip" title="Version1.01 downloaded 142 times" >Small implementation of Shabal (update) (142)</a>
<p>For instance, when compiled with GCC-4.4.1 on an Intel x86 Linux system (32-bit mode), with the &#8220;-Os -fomit-frame-pointer&#8221; flags, the footprint of Shabal is <strong>698 bytes</strong>. Yet it still hash data with a bandwidth of<strong> 109 MB/s on a 2.4 GHz Core2 machine</strong>, which is similar to what can be achieved with heavyweight, assembly-optimized implementations of SHA-256 and SHA-512 on the same platform.</p>
<p>See the <em>shabal_small.h</em> header file for documentation on the API. The code itself is written in C and should compile on any platform with a C89 compiler (&#8220;ANSI C&#8221;), subject to the only restriction that the architecture should be octet oriented (i.e. an &#8216;unsigned char&#8217; shall have a width of exactly 8 bits, no more; only a few exotic embedded DSP do not follow that rule, and the code will cleanly abort compilation in such a case).</p>
<p>(c) 2010 SAPHIR project. This software is provided &#8216;as-is&#8217;, without any express or implied warranty. In no event will the authors be held liable for any damages arising from the use of this software.</p>
<p>Permission is granted to anyone to use this software for any purpose, including commercial applications, and to alter it and redistribute it freely, subject to no restriction.</p>
<p>Technical remarks and questions can be addressed to:  thomas.pornin at cryptolog.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=108</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FPGA Implementation of Shabal: An Update</title>
		<link>http://www.shabal.com/?p=103</link>
		<comments>http://www.shabal.com/?p=103#comments</comments>
		<pubDate>Mon, 08 Mar 2010 17:37:59 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Implementations]]></category>
		<category><![CDATA[Shabal]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=103</guid>
		<description><![CDATA[An update of the short note &#8220;FPGA Implementation of Shabal&#8221; is available in the download section. This new version takes into account some comments on the first version. Authors: Romain Feron and Julien Francq (EADS Defence &#38; Security, Cyber Security Customer Solutions Center) This work was partially supported by the French Agence Nationale de la [...]]]></description>
			<content:encoded><![CDATA[<p>An update of the short note &#8220;<a href="https://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=FPGA-Implementation-of-Shabal-First-Results.pdf" target="_blank">FPGA Implementation of Shabal</a>&#8221; is available in the download section.<span id="more-103"></span> This new version takes into account some comments on the first version.</p>
<p><strong>Authors:</strong> Romain Feron and Julien Francq (EADS  Defence &amp; Security, Cyber Security Customer Solutions Center)</p>
<p>This work was partially supported by the French <a href="http://www.agence-nationale-recherche.fr/" target="_blank">Agence  Nationale de la Recherche</a> through the <a href="http://www.saphir2.fr/" target="_blank">SAPHIR2 project</a> under  Contract ANR-08-VERS-014.</p>
<a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=FPGA-Implementation-of-Shabal-First-ResultsV2.0.pdf" title="Version2.0 downloaded 226 times" >FPGA Implementation of Shabal: Our First Results (update) (226)</a>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=103</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FPGA Implementation of Shabal</title>
		<link>http://www.shabal.com/?p=100</link>
		<comments>http://www.shabal.com/?p=100#comments</comments>
		<pubDate>Tue, 16 Feb 2010 14:32:55 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Implementations]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=100</guid>
		<description><![CDATA[A short note is available in the download section that describes a new hardware implementation of Shabal. The results outperform the state-of-the-art. In particular, Shabal can achieve a high throughput, and can also be implemented with very low area. Authors: Romain Feron and Julien Francq (EADS Defence &#38; Security, Cyber Security Customer Solutions Center) This [...]]]></description>
			<content:encoded><![CDATA[<p>A short note is available in the download section that describes a new hardware implementation of Shabal. The results outperform the state-of-the-art.<span id="more-100"></span> In particular, Shabal can achieve a high throughput, and can also be implemented with very low area.</p>
<p><strong>Authors:</strong> Romain Feron and Julien Francq (EADS Defence &amp; Security, Cyber Security Customer Solutions Center)</p>
<p>This work was partially supported by the French <a href="http://www.agence-nationale-recherche.fr/" target="_blank">Agence Nationale de la Recherche</a> through the <a href="http://www.saphir2.fr" target="_blank">SAPHIR2 project</a> under Contract ANR-08-VERS-014.</p>
<a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=FPGA-Implementation-of-Shabal-First-Results.pdf" title="Version1/15/2010 downloaded 334 times" >FPGA Implementation of Shabal: Our First Results (334)</a>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=100</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shabal and the distinguishers</title>
		<link>http://www.shabal.com/?p=84</link>
		<comments>http://www.shabal.com/?p=84#comments</comments>
		<pubDate>Tue, 19 Jan 2010 16:18:17 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Shabal]]></category>

		<guid isPermaLink="false">http://www.shabal.com/?p=84</guid>
		<description><![CDATA[Anne Canteaut gave a presentation during the  &#8220;Early Symmetric Crypto&#8221; (ESC 2010) seminar at Luxembourg University. Title: Capturing the existence of distinguishers into indifferentiability proofs for hash functions Abstract: Indifferentiability proofs for hash functions show that the underlying mode of operation used with an ideal compression function (or with an ideal block cipher) is indifferentiable [...]]]></description>
			<content:encoded><![CDATA[<p>Anne Canteaut gave a presentation during the  &#8220;Early Symmetric Crypto&#8221; (<a href="https://cryptolux.org/ESC/ESC_2010" target="_blank">ESC 2010</a>) seminar at Luxembourg University.<span id="more-84"></span></p>
<p><strong>Title:</strong> Capturing the existence of distinguishers into indifferentiability proofs for hash functions</p>
<p><strong>Abstract:</strong><br />
Indifferentiability proofs for hash functions show that the underlying mode of operation used with an ideal compression function (or with an ideal block cipher) is indifferentiable from a random oracle (up to a certain number of calls to the compression function). However, for many practical hash functions, we can provide evidence that the compression function is not uniformly chosen at random (the extremal case is the case where it is fixed). It is then important to determine how the choice of a &#8220;biased&#8221; compression function affects the security of the hash function. Here, we show how some indifferentiability proofs can be adapted to the case where the compression function is uniformly chosen at random in some subset of all possible compression functions, instead of all of them. For those distinguishers, we give new bounds on the security of several modes of operation, including chop-MD and Shabal&#8217;s mode of operation.</p>
<p>(joint work with E. Bresson, T. Fuhr, A. Gouget, T. Icart, M. Naya-Plasencia, P. Paillier, J.-R. Reinhard, M. Videau)</p>
<a class="downloadlink" href="http://www.shabal.com/wp-content/plugins/download-monitor/download.php?id=Canteaut-esc1.pdf" title=" downloaded 184 times" >Capturing the existence of distinguishers into indifferentiability proofs (ESC 2010) (184)</a>
]]></content:encoded>
			<wfw:commentRss>http://www.shabal.com/?feed=rss2&amp;p=84</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
