A new criterion for avoiding the propagation
- f linear relations through an Sbox
Christina Boura and Anne Canteaut
INRIA Paris-Rocquencourt DTU Compute
March 13, 2013
1 / 23
A new criterion for avoiding the propagation of linear relations - - PowerPoint PPT Presentation
A new criterion for avoiding the propagation of linear relations through an Sbox Christina Boura and Anne Canteaut INRIA Paris-Rocquencourt DTU Compute March 13, 2013 1 / 23 Outline Introduction 1 The notion of ( v, w ) -linearity 2
INRIA Paris-Rocquencourt DTU Compute
1 / 23
1
2
3
4
5
2 / 23
Introduction
1
2
3
4
5
3 / 23
Introduction
4 / 23
Introduction
4 / 23
Introduction
5 / 23
Introduction
6 / 23
Introduction
6 / 23
Introduction
6 / 23
Introduction
6 / 23
The notion of (v, w)-linearity
1
2
3
4
5
7 / 23
The notion of (v, w)-linearity
2 into Fm 2 . Then,
2 and W ⊂ Fm 2
8 / 23
The notion of (v, w)-linearity
9 / 23
The notion of (v, w)-linearity
9 / 23
The notion of (v, w)-linearity
2 → F2 with
10 / 23
The notion of (v, w)-linearity
2 → F2 with
10 / 23
The notion of (v, w)-linearity
2 → F2 with
10 / 23
The notion of (v, w)-linearity
2 → F2 with
2 → F2 that is (v, 1)-linear w.r.t. V can be written as
10 / 23
The notion of (v, w)-linearity
2 → F2 with
2 → F2 that is (v, 1)-linear w.r.t. V can be written as
10 / 23
The notion of (v, w)-linearity
2
11 / 23
The notion of (v, w)-linearity
12 / 23
Analysis of 4-bit optimal Sboxes
1
2
3
4
5
13 / 23
Analysis of 4-bit optimal Sboxes
14 / 23
Analysis of 4-bit optimal Sboxes
14 / 23
Analysis of 4-bit optimal Sboxes
(v, w) Q (2,1) (2,2) (2,3) (2,4) (3,1) (3,2) (3,3) (3,4) G0 3 35 19 5 7 1 G1 3 35 23 3 7 1 G2 3 35 23 3 7 1 G3 35 5 G4 35 5 G5 35 5 G6 35 5 G7 35 5 G8 3 35 19 5 7 1 G9 1 35 13 3 G10 1 35 13 3 G11 35 5 G12 35 5 G13 35 5 G14 1 35 13 3 G15 1 35 11 1 3 15 / 23
Application to Hamsi
1
2
3
4
5
16 / 23
Application to Hamsi
message block chain value message block 256-bit 256-bit chain value
Concatenation
32-bit
Permutation P
17 / 23
Application to Hamsi
18 / 23
Application to Hamsi
19 / 23
Application to Hamsi
19 / 23
Application to Hamsi
19 / 23
Application to Hamsi
20 / 23
Application to Hamsi
21 / 23
Application to Hamsi
21 / 23
Conclusion
1
2
3
4
5
22 / 23
Conclusion
23 / 23
Conclusion
23 / 23