-
Shabal and the distinguishers
Posted on January 19th, 2010 No commentsAnne Canteaut gave a presentation during the “Early Symmetric Crypto” (ESC 2010) seminar at Luxembourg University.
Title: Capturing the existence of distinguishers into indifferentiability proofs for hash functions
Abstract:
Indifferentiability proofs for hash functions show that the underlying mode of operation used with an ideal compression function (or with an ideal block cipher) is indifferentiable from a random oracle (up to a certain number of calls to the compression function). However, for many practical hash functions, we can provide evidence that the compression function is not uniformly chosen at random (the extremal case is the case where it is fixed). It is then important to determine how the choice of a “biased” compression function affects the security of the hash function. Here, we show how some indifferentiability proofs can be adapted to the case where the compression function is uniformly chosen at random in some subset of all possible compression functions, instead of all of them. For those distinguishers, we give new bounds on the security of several modes of operation, including chop-MD and Shabal’s mode of operation.(joint work with E. Bresson, T. Fuhr, A. Gouget, T. Icart, M. Naya-Plasencia, P. Paillier, J.-R. Reinhard, M. Videau)
Capturing the existence of distinguishers into indifferentiability proofs (ESC 2010) (184)Leave a reply


Recent Comments