Indifferentiability with Distinguishers: Why Shabal Does Not Require Ideal Ciphers

Abstract : Shabal is based on a new provably secure mode of operation. Some related-key distinguishers for the underlying keyed permutation have been exhibited recently by Aumasson et al. and Knudsen et al., but with no visible impact on the security of Shabal. This paper then aims at extensively studying such distinguishers for the keyed permutation used in Shabal, and at clarifying the impact that they exert on the security of the full hash function. Most interestingly, a new security proof for Shabal's mode of operation is provided where the keyed permutation is not assumed to be an ideal cipher anymore, but observes a distinguishing property i.e., an explicit relation verified by all its inputs and outputs. As a consequence of this extended proof, all known distinguishers for the keyed permutation are proven not to weaken the security of Shabal. In our study, we provide the foundation of a generalization of the indifferentiability framework to biased random primitives, this part being of independent interest.
Type de document :
Rapport
[Research Report] 2009/299, IACR Cryptology ePrint Archive. 2009
Liste complète des métadonnées

https://hal.inria.fr/hal-00771272
Contributeur : Marion Videau <>
Soumis le : mardi 8 janvier 2013 - 12:23:50
Dernière modification le : mardi 25 octobre 2016 - 17:02:18

Identifiants

  • HAL Id : hal-00771272, version 1

Collections

Citation

Emmanuel Bresson, Anne Canteaut, Benoit Chevallier-Mames, Christophe Clavier, Thomas Fuhr, et al.. Indifferentiability with Distinguishers: Why Shabal Does Not Require Ideal Ciphers. [Research Report] 2009/299, IACR Cryptology ePrint Archive. 2009. 〈hal-00771272〉

Partager

Métriques

Consultations de la notice

377