On probabilities of differential trails in the bash-f sponge function
We propose two methods to obtain lower bounds on the weights of differential trails in the Bash-f sponge function. Our bounds restrict the probabilities of the trails from above and can be used to justify the security of cryptographic algorithms based on Bash-f against differential attacks. For the full 24-round trails, our best bound on the probabilities is 2-386.
Download file
Counter downloads: 121
Keywords
sponge-функция, S-блок, разностный криптоанализ, разностная траектория, sponge function, S-box, differential cryptanalysis, differential trailAuthors
Name | Organization | |
Agievich S. V. | Belarusian State University | agievich@bsu.by |
Maslau A. S. | Belarusian State University | maslov@bsu.by |
Yarashenya Yu. S. | Belarusian State University | yuliya_10.06@mail.ru |
References
Daemen J. and Van Assche G. Differential propagation analysis of Keccak // FSE'2012. LNCS. 2012. V. 7549. P. 422-441.
Mella S., Daemen J., and Van Assche G. New techniques for trail bounds and application to differential trails in Keccak // IACR Trans. Symmetric Cryptology. 2017. No. 1. P. 329-357.
Agievich S., Marchuk V., Maslau A., and Semenov V. Bash-f: another LRX sponge function // Математические вопросы криптографии. 2017. Т. 8. №2. С. 7-28.

On probabilities of differential trails in the bash-f sponge function | Applied Discrete Mathematics. Supplement. 2019. № 12. DOI: 10.17223/2226308X/12/27
Download full-text version
Counter downloads: 2700