Cryptanalysis Results on Spook - Bringing Full-Round Shadow-512 to the Light
Patrick Derbez, Paul Huynh, Virginie Lallemand, María Naya-Plasencia, Léo Perrin, André Schrottenloher
Abstract
Spook [BBB + 19] is one of the 32 candidates that has made it to the second round of the NIST Lightweight Cryptography Standardization process, and is particularly interesting since it proposes differential side channel resistance. In this paper, we present practical distinguishers of the full 6-step version of the underlying permutations of Spook, namely Shadow-512 and Shadow-384, solving challenges proposed by the designers on the permutation. We also propose practical forgeries with 4-step Shadow for the S1P mode of operation in the nonce misuse scenario, which is allowed by the CIML2 security game considered by the authors. All the results presented in this paper have been implemented.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8287b45a-7b80-47f0-9719-b30d2ee2c0b9Cited by top-tier papers1
Ask how each one uses itRelated papers
- Tight Preimage Resistance of the Sponge ConstructionCharlotte Lefevre, Bart MenninkCRYPTO 2022 · 15 citations
- Twin Column Parity Mixers and Gaston - A New Mixing Layer and PermutationSolane El Hirch, Joan Daemen, Raghvendra Rohit, Rusydi H. MakarimCRYPTO 2023 · 2 citations
- Pseudorandom Black Swans: Cache Attacks on CTR_DRBGShaanan Cohney, Andrew Kwong, Shahar Paz, Daniel Genkin et al.S&P 2020 · 36 citations
- New Representations of the AES Key ScheduleGaëtan Leurent, Clara PernotEUROCRYPT 2021 · 33 citations
- The Insecurity of Masked Comparisons: SCAs on ML-KEM's FO-TransformJulius Hermelink, Kai-Chun Ning, Richard Petri, Emanuele StriederCCS 2024 · 3 citations
