Cryptology ePrint Archive: Report 2016/554

Another view of the division property

Christina Boura and Anne Canteaut

Abstract: A new distinguishing property against block ciphers, called the division property, was introduced by Todo at Eurocrypt 2015. Our work gives a new approach to it by the introduction of the notion of parity sets. First of all, this new notion permits us to formulate and characterize in a simple way the division property of any order. At a second step, we are interested in the way of building distinguishers on a block cipher by considering some further properties of parity sets, generalising the division property. We detail in particular this approach for substitution-permutation networks. To illustrate our method, we provide low-data distinguishers against reduced-round Present. These distinguishers reach a much higher number of rounds than generic distinguishers based on the division property and demonstrate, amongst others, how the distinguishers can be improved when the properties of the linear and the Sbox layer are taken into account. At last, this work provides an analysis of the resistance of Sboxes against this type of attacks, demonstrates links with the algebraic normal form of an Sbox as well as its inverse Sbox and exhibit design criteria for Sboxes to resist such attacks.

Category / Keywords: secret-key cryptography / division property, integral attacks, Sboxes, PRESENT

Original Publication (in the same form): IACR-CRYPTO-2016

Date: received 2 Jun 2016

Contact author: Anne Canteaut at inria fr

Available format(s): PDF | BibTeX Citation

Version: 20160603:161832 (All versions of this report)

Short URL:

Discussion forum: Show discussion | Start new discussion

[ Cryptology ePrint archive ]