Designing symmetric ciphers for particular applications becomes a hot topic. At EUROCRYPT 2020, Naito, Sasaki and Sugawara invented the threshold implementation friendly cipher SKINNYe-64-256 to meet the requirement of the authenticated encryption PFB_Plus. Soon, Thomas Peyrin pointed out that SKINNYe-64-256 may lose the security expectation due the new tweakey schedule. Although the security issue of SKINNYe-64-256 is still unclear, Naito et al. decided to introduce SKINNYe-64-256 v2 as a response. In this paper, we give a formal cryptanalysis on the new tweakey schedule of SKINNYe-64-256 and discover unexpected differential cancellations in the tweakey schedule. For example, we find the number of cancellations can be up to 8 within ...
We analyze the multi-user (mu) security of a family of nonce-based authentication encryption (nAE) s...
One of the ultimate goals of symmetric-key cryptography is to find a rigorous theoretical framework ...
Evaluating resistance of ciphers against differential cryptanalysis is essential to define the numbe...
Skinny is a lightweight tweakable block cipher which received a great deal of cryptanalytic attentio...
In April 2018, Beierle et al. launched the 3rd SKINNY cryptanalysis competition, a contest that aime...
At CRYPTO’16, Beierle et al. presented SKINNY, a family of lightweight tweakable block ciphers inten...
In CRYPTO’16, a new family of tweakable lightweight block ciphers - SKINNY was introduced. Denoting ...
SKINNY is a family of lightweight tweakable block ciphers designed to have the smallest hardware foo...
Lightweight cryptography is characterized by the need for low implementation cost, while still provi...
Block ciphers are among the mostly widely used symmetric-key cryptographic primitives, which are fun...
The boomerang and rectangle attacks are adaptions of differential cryptanalysis that regard the targ...
International audienceEvaluating resistance of ciphers against differential cryptanalysis is essenti...
The SKINNY family of lightweight block ciphers is well-researched in terms of standard cryptanalysis...
Resistance against differential cryptanalysis is an important design criteria for any modern block c...
Abstract. We propose the TWEAKEY framework with goal to unify the design of tweakable block ciphers ...
We analyze the multi-user (mu) security of a family of nonce-based authentication encryption (nAE) s...
One of the ultimate goals of symmetric-key cryptography is to find a rigorous theoretical framework ...
Evaluating resistance of ciphers against differential cryptanalysis is essential to define the numbe...
Skinny is a lightweight tweakable block cipher which received a great deal of cryptanalytic attentio...
In April 2018, Beierle et al. launched the 3rd SKINNY cryptanalysis competition, a contest that aime...
At CRYPTO’16, Beierle et al. presented SKINNY, a family of lightweight tweakable block ciphers inten...
In CRYPTO’16, a new family of tweakable lightweight block ciphers - SKINNY was introduced. Denoting ...
SKINNY is a family of lightweight tweakable block ciphers designed to have the smallest hardware foo...
Lightweight cryptography is characterized by the need for low implementation cost, while still provi...
Block ciphers are among the mostly widely used symmetric-key cryptographic primitives, which are fun...
The boomerang and rectangle attacks are adaptions of differential cryptanalysis that regard the targ...
International audienceEvaluating resistance of ciphers against differential cryptanalysis is essenti...
The SKINNY family of lightweight block ciphers is well-researched in terms of standard cryptanalysis...
Resistance against differential cryptanalysis is an important design criteria for any modern block c...
Abstract. We propose the TWEAKEY framework with goal to unify the design of tweakable block ciphers ...
We analyze the multi-user (mu) security of a family of nonce-based authentication encryption (nAE) s...
One of the ultimate goals of symmetric-key cryptography is to find a rigorous theoretical framework ...
Evaluating resistance of ciphers against differential cryptanalysis is essential to define the numbe...