Paper 2023/789

Where are the constants? New Insights On The Role of Round Constant Addition in The SymSum Distinguisher

Sahiba Suryawanshi, Indian Institute of Technology Bhilai
Dhiman Saha, Indian Institute of Technology Bhilai
Abstract

The current work makes a systematic attempt to describe the effect of the relative order of round constant ( RCon) addition in the round function of an SPN cipher on its algebraic structure. The observations are applied to the SymSum distinguisher, introduced by Saha et al. in FSE 2017 which is one of the best distinguishers on the SHA3 hash function reported in literature. Results show that certain ordering (referred to as Type-LCN) of RCon makes the distinguisher less effective but it still works with some limitations. Results in the form of new SymSum distinguishers are reported on concrete Type-LCN constructions - NIST LWC competition finalist Xoodyak-Hash and its internal permutation Xoodoo. New linear structures are also reported on Xoodoo that augment the distinguisher to penetrate more rounds. Final results include SymSum distinguishers on 7 rounds of Xoodoo and 5 rounds of Xoodyak-Hash with complexity 2^128 and 2^32 , respectively. All practical distinguishers have been verified. The characterization encompassing the algebraic structure and effect of RCon provided by the current work improves the under- standing of SymSum in general and constitutes one of the first such result on Xoodyak-Hash and Xoodoo.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Higher Order DerivativeSPN cipherSymSum DistinguisherZeroSum DistinguisherXoodoo · Xoodyak-Hash.
Contact author(s)
sahibas @ iitbhilai ac in
dhiman @ iitbhilai ac in
History
2023-06-06: approved
2023-05-30: received
See all versions
Short URL
https://ia.cr/2023/789
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2023/789,
      author = {Sahiba Suryawanshi and Dhiman Saha},
      title = {Where are the constants? New Insights On The Role of Round Constant Addition in The {SymSum} Distinguisher},
      howpublished = {Cryptology {ePrint} Archive, Paper 2023/789},
      year = {2023},
      url = {https://eprint.iacr.org/2023/789}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.