Strong and Tight Security Guarantees Against Integral Distinguishers2021
Conference / Medium
Baptiste Lambin Phil Hebborn Gregor Leander Yosuke Todo
Research Hub A: Kryptographie der Zukunft
RC 1: Cryptography against Mass Surveillance
Integral attacks belong to the classical attack vectors against any given block ciphers. However, providing arguments that a given cipher is resistant against those attacks is notoriously difficult. In this paper, based solely on the assumption of independent round keys, we develop significantly stronger arguments than what was possible before: our main result is that we show how to argue that the sum of ciphertexts over any possible subset of plaintext is key-dependent, i.e., the non existence of integral distinguishers.