Cryptanalysis of Full SCARF
Antonio Flórez-Gutiérrez, Eran Lambooij, Gaëtan Leurent, Håvard Raddum, Tyge Tiessen, Michiel Verbauwhede
摘要
SCARF is a tweakable block cipher dedicated to cache address randomization, proposed at the USENIX Security conference. It has a 10bit block, 48-bit tweak, and 240-bit key. SCARF is aggressively optimized to meet the harsh latency constraints of cache address randomization, and uses a dedicated model for its security claim. The full version of SCARF has 8 rounds, and its designers claim security up to 2 40 queries and 2 80 computations. In this work we present a distinguisher against 6-round SCARF under the collision model with time and query complexity 2 30 , and a key-recovery attack against the full 8-round SCARF under the encryption-decryption model with 2 39 queries and time 2 76.2 . As part of the attack, we present a novel method to compute the minimal number of right pairs following a differential characteristic when the input pairs are restricted to a subspace of the domain of the primitive.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz 等USENIX Security 2019 · 被引用 221 次
- MIRAGE: Mitigating Conflict-Based Cache Attacks with a Practical Fully-Associative DesignGururaj Saileshwar, Moinuddin K. QureshiUSENIX Security 2021 · 被引用 105 次
- Differential Cryptanalysis in the Fixed-Key ModelTim Beyne, Vincent RijmenCRYPTO 2022 · 被引用 28 次
- SCARF - A Low-Latency Block Cipher for Secure Cache-RandomizationFederico Canale, Tim Güneysu, Gregor Leander, Jan Philipp Thoma 等USENIX Security 2023
相关 Paper
- Truncated Boomerang Attacks and Application to AES-Based CiphersAugustin Bariant, Gaëtan LeurentEUROCRYPT 2023 · 被引用 29 次
- Scatter and Split Securely: Defeating Cache Contention and Occupancy AttacksLukas Giner, Stefan Steinegger, Antoon Purnal, Maria Eichlseder 等S&P 2023
- Better Steady than Speedy: Full Break of SPEEDY-7-192Christina Boura, Nicolas David, Rachelle Heim Boissier, María Naya-PlasenciaEUROCRYPT 2023 · 被引用 16 次
- A Generic Algorithm for Efficient Key Recovery in Differential Attacks - and its Associated ToolChristina Boura, Nicolas David, Patrick Derbez, Rachelle Heim Boissier 等EUROCRYPT 2024 · 被引用 11 次
- Meet-in-the-Middle Attacks on Full ChiLowEran Lambooij, Patrick Neumann, Michiel Verbauwhede, Shichang Wang 等CRYPTO 2026
