[The Ketje cryptanalysis contest] Improved Attacks on Round-Reduced Ketje

Song Ling (Dr)

Oct 29, 2017, 2:18:34 AM10/29/17
Dear Ketje Team and all,

In response to “The Ketje cryptanalysis contest”: https://keccak.team/ketje_contest.html, we (Ling, Jian, Danping), found improved attacks on Ketje using a new mixed integer linear programming (MILP) model, based on the prior works by Huang et al. [1] and Li et al [2]. Our attacks cover 7 rounds in the nonce respected setting and/or have reduced complexities (than those of [2,3]). The new MILP model and more details of the attacks are available here: https://eprint.iacr.org/2017/1030.

Best Regards,

Ling Song (1,2,3), Jian Guo(2), Danping Shi (1,3)

1. State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, China
2. Nanyang Technological University, Singapore
3. Data Assurance and Communication Security Research Center, Chinese Academy of Sciences, China

[1] Huang, S., Wang, X., Xu, G., Wang, M., Zhao, J.: Conditional Cube Attack on Reduced-Round Keccak Sponge Function. In: Coron, J., Nielsen, J.B. (eds.) Advances in Cryptology - EUROCRYPT 2017 - 36th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Paris, France, April 30 - May 4, 2017, Proceedings, Part II. LNCS, vol. 10211, pp. 259–288 (2017)
[2] Li, Z., Bi, W., Dong, X., Wang, X.: Improved Conditional Cube Attacks on Keccak Keyed Modes with MILP Method. to appear in ASIACRYPT 2017, available at https://eprint.iacr.org/2017/804 (2017)
[3] Dong, X., Li, Z., Wang, X., Qin, L.: Cube-like Attack on Round-Reduced Initialization of Ketje Sr. IACR Trans. Symmetric Cryptol. 2017(1), 259–280 (2017).

Nov 2, 2017, 3:28:39 AM11/2/17
to Song Ling (Dr), crypto-co...@googlegroups.com

Dear Ling Song, Jian Guo and Danping Shi,

we are impressed by the rate at which you produce new results on Keccak and relatives! Thanks for sharing these new results, clearly we will consider them for the Ketje cryptanalysis prize.

Kind regards,
Guido, Joan, Michaël, Gilles and Ronny
