Shabal
A submission to NIST's Cryptographic Hash Algorithm Competition
-
Indifferentiability with Distinguishers: Why Shabal Does Not Require Ideal Ciphers
Posted on May 6th, 2009 No commentsShabal is based on a new provably secure mode of operation. Some related-key distinguishers for the underlying keyed permutation have been exhibited recently by Aumasson et al. and Knudsen et al., but with no visible impact on the security of Shabal. This paper then aims at extensively studying such distinguishers for the keyed permutation used in Shabal, and at clarifying the impact that they exert on the security of the full hash function. Read the rest of this entry »


Recent Comments