International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Analyzing the Linear Keystream Biases in AEGIS

Authors:
Maria Eichlseder , Graz University of Technology, Graz, Austria
Marcel Nageler , Graz University of Technology, Graz, Austria
Robert Primas , Graz University of Technology, Graz, Austria
Download:
DOI: 10.13154/tosc.v2019.i4.348-368
URL: https://tosc.iacr.org/index.php/ToSC/article/view/8468
Search ePrint
Search Google
Abstract: AEGIS is one of the authenticated encryption designs selected for the final portfolio of the CAESAR competition. It combines the AES round function and simple Boolean operations to update its large state and extract a keystream to achieve an excellent software performance. In 2014, Minaud discovered slight biases in the keystream based on linear characteristics. For family member AEGIS-256, these could be exploited to undermine the confidentiality faster than generic attacks, but this still requires very large amounts of data. For final portfolio member AEGIS-128, these attacks are currently less efficient than generic attacks. We propose improved keystream approximations for the AEGIS family, but also prove upper bounds below 2−128 for the squared correlation contribution of any single suitable linear characteristic.
Video from TOSC 2020
BibTeX
@article{tosc-2020-30098,
  title={Analyzing the Linear Keystream Biases in AEGIS},
  journal={IACR Transactions on Symmetric Cryptology},
  publisher={Ruhr-Universität Bochum},
  volume={2019, Issue 4},
  pages={348-368},
  url={https://tosc.iacr.org/index.php/ToSC/article/view/8468},
  doi={10.13154/tosc.v2019.i4.348-368},
  author={Maria Eichlseder and Marcel Nageler and Robert Primas},
  year=2020
}