From Related-Key Distinguishers to Related-Key-Recovery on Even-Mansour Constructions

Pierre Karpman

Abstract: We show that a distinguishing attack in the related key model on an Even-Mansour block cipher can readily be converted into an extremely efficient key recovery attack. Concerned ciphers include in particular all iterated Even-Mansour schemes with independent keys. We apply this observation to the Caesar candidate PrÝst-OTR and are able to recover the whole key with a number of requests linear in its size. This improves on recent forgery attacks in a similar setting.

Category / Keywords: secret-key cryptography / Even-Mansour, related-key attacks, PrÝst-OTR

