Linear Biases in AEGIS Keystream
Brice Minaud
ANSSI, France
SAC – August 15, 2014
Linear Biases in AEGIS Keystream Brice Minaud ANSSI, France SAC - - PowerPoint PPT Presentation
Linear Biases in AEGIS Keystream Brice Minaud ANSSI, France SAC August 15, 2014 Plan 1 Blockwise Stream Ciphers 2 Presentation of AEGIS 3 Linear Biases in AEGIS 1/22 Blockwise Stream Ciphers 2/22 Authenticated Encryption Schemes C
ANSSI, France
SAC – August 15, 2014
1
2
3
1/22
2/22
i
3/22
3/22
3/22
3/22
AEGIS, Artemia, Ascon, CBEAM, ICEPOLE, Keyak, Ketje, MORUS, PAES, PANDA, π-Cipher, 2/3 PRIMATEs, STRIBOB, Tiaoxin...
3/22
4/22
4/22
4/22
5/22
5/22
6/22
7/22
8/22
9/22
10/22
1 Initialization. 2 Processing of associated data. 3 Encryption. 4 Finalization and tag generation. 11/22
12/22 128
128
128
128
128
13/22 128
128
128
128
128
14/22 128
128
128
128
128
128
15/22
16/22
16/22
17/22
18/22
Si,0 R Si,1 R R R R Si+1,1 Si+2,2 * *
18/22
Si,0 R Si,1 R R R R Si+1,1 Si+2,2 * *
19/22
Si,0 R Si,1 R Si,2 R R R R R R R R Si+2,2 * * * * R
20/22
21/22
21/22
21/22
21/22
21/22
21/22
21/22
22/22