Lune

CRYPTO2023顶会

Layout Graphs, Random Walks and the t-Wise Independence of SPN Block Ciphers

Tianren Liu, Angelos Pelecanos, Stefano Tessaro, Vinod Vaikuntanathan

2023年份
9被引次数
1顶会引用

摘要

We continue the study of tt-wise independence of substitution-permutation networks (SPNs) initiated by the recent work of Liu, Tessaro, and Vaikuntanathan (CRYPTO 2021). Our key technical result shows that when the S-boxes are randomly and independently chosen and kept secret, an rr-round SPN with input length n=b⋅kn = b \cdot k is 2−Θ(n)2^{-\Theta(n)}-close to tt-wise independent within r=O(min⁡{k,log⁡t})r = O(\min\{k, \log t\}) rounds for any tt almost as large as 2b/22^{b/2}. Here, bb is the input length of the S-box and we assume that the underlying mixing achieves maximum branch number. We also analyze the special case of AES parameters (with random S-boxes), and show it is 2−1282^{-128}-close to pairwise independent in 77 rounds. Central to our result is the analysis of a random walk on what we call the layout graph, a combinatorial abstraction that captures equality and inequality constraints among multiple SPN evaluations. We use our technical result to show concrete security bounds for SPNs with actual block cipher parameters and small-input SS-boxes. (This is in contrast to the large body of results on ideal-model analyses of SPNs.) For example, for the censored-AES block cipher, namely AES with most of the mixing layers removed, we show that 192 rounds suffice to attain 2−1282^{-128}-closeness to pairwise independence. The prior such result for AES (Liu, Tessaro and Vaikuntanathan, CRYPTO 2021) required more than 9000 rounds.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖