Strong and Tight Security Guarantees against Integral Distinguishers

Phil Hebborn, Baptiste Lambin, Gregor Leander, and Yosuke Todo


Integral attacks belong to the classical attack vectors against any given block ciphers. However, providing arguments that a given cipher is resistant against those attacks is notoriously difficult. In this paper, based solely on the assumption of independent round keys, we develop significantly stronger arguments than what was possible before: our main result is that we show how to argue that the sum of ciphertexts over any possible subset of plaintext is key-dependent, i.e., the non existence of integral distinguishers.

Secret-key cryptography
A minor revision of an IACR publication in ASIACRYPT 2021
Block Cipher · Integral Distinguisher
