Distinguisher for Shabal's Permutation Function.

Peter Novotney · 2010

In this note we consider the Shabal permutation function P as a block cipher with input Ap,Bp and key C,M and describe a distinguisher with a data complexity of 2 23 random inputs with a given difference. If the attacker can control one chosen bit of Bp, only 2 21 inputs with a given difference are required on average. This distinguisher does not appear to lead directly to an attack on the full Shabal construction. 1

Read the paper · More papers on PaperTik