Lower Bounds on the Degree of Block Ciphers2020
Research Hub A: Kryptographie der Zukunft
RC 1: Cryptography against Mass Surveillance
Only the method to estimate the upper bound of the algebraic degree on block ciphers is known so far, but it is not useful for the designer to guarantee the security. In this paper we provide meaningful lower bounds on the algebraic degree of modern block ciphers.