Cryptanalysis of Full SCARF
Antonio Flórez-Gutiérrez, Eran Lambooij, Gaëtan Leurent, Håvard Raddum, Tyge Tiessen, Michiel Verbauwhede
Abstract
SCARF is a tweakable block cipher dedicated to cache address randomization, proposed at the USENIX Security conference. It has a 10bit block, 48-bit tweak, and 240-bit key. SCARF is aggressively optimized to meet the harsh latency constraints of cache address randomization, and uses a dedicated model for its security claim. The full version of SCARF has 8 rounds, and its designers claim security up to 2 40 queries and 2 80 computations. In this work we present a distinguisher against 6-round SCARF under the collision model with time and query complexity 2 30 , and a key-recovery attack against the full 8-round SCARF under the encryption-decryption model with 2 39 queries and time 2 76.2 . As part of the attack, we present a novel method to compute the minimal number of right pairs following a differential characteristic when the input pairs are restricted to a subspace of the domain of the primitive.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz et al.USENIX Security 2019 · 221 citations
- MIRAGE: Mitigating Conflict-Based Cache Attacks with a Practical Fully-Associative DesignGururaj Saileshwar, Moinuddin K. QureshiUSENIX Security 2021 · 105 citations
- Differential Cryptanalysis in the Fixed-Key ModelTim Beyne, Vincent RijmenCRYPTO 2022 · 28 citations
- SCARF - A Low-Latency Block Cipher for Secure Cache-RandomizationFederico Canale, Tim Güneysu, Gregor Leander, Jan Philipp Thoma et al.USENIX Security 2023
Related papers
- Truncated Boomerang Attacks and Application to AES-Based CiphersAugustin Bariant, Gaëtan LeurentEUROCRYPT 2023 · 29 citations
- Scatter and Split Securely: Defeating Cache Contention and Occupancy AttacksLukas Giner, Stefan Steinegger, Antoon Purnal, Maria Eichlseder et al.S&P 2023
- Better Steady than Speedy: Full Break of SPEEDY-7-192Christina Boura, Nicolas David, Rachelle Heim Boissier, María Naya-PlasenciaEUROCRYPT 2023 · 16 citations
- A Generic Algorithm for Efficient Key Recovery in Differential Attacks - and its Associated ToolChristina Boura, Nicolas David, Patrick Derbez, Rachelle Heim Boissier et al.EUROCRYPT 2024 · 11 citations
- Meet-in-the-Middle Attacks on Full ChiLowEran Lambooij, Patrick Neumann, Michiel Verbauwhede, Shichang Wang et al.CRYPTO 2026
