Higher-Order Differential

Influence of the Linear Layer on the Algebraic Degree in SP-Networks

We consider SPN schemes, i.e., schemes whose non-linear layer is defined as the parallel application of t=1 independent S-Boxes over GF(2^n) and whose linear layer is defined by the multiplication with a nt x nt matrix over GF(2). Even if the …

An Algebraic Attack on Ciphers with Low-Degree Round Functions: Application to Full MiMC

Algebraically simple PRFs, ciphers, or cryptographic hash functions are becoming increasingly popular, for example due to their attractive properties for MPC and new proof systems (SNARKs, STARKs, among many others). In this paper, we focus on the …

An Algebraic Attack on Ciphers with Low-Degree Round Functions: Application to Full MiMC

Algebraically simple PRFs, ciphers, or cryptographic hash functions are becoming increasingly popular, for example due to their attractive properties for MPC and new proof systems (SNARKs, STARKs, among many others). In this paper, we focus on the …

Algebraic Cryptanalysis of Variants of Frit

Frit is a cryptographic 384-bit permutation recently proposed by Simon et al. and follows a novel design approach for built-in countermeasures against fault attacks. We analyze the cryptanalytic security of Frit in different use cases and propose …