Matching attacks on Romulus‐M

Makoto Habu, Kazuhiko Minematsu, Tetsu Iwata · IET Information Security · 2022

Abstract This paper considers a problem of identifying matching attacks against Romulus‐M, one of the 10 finalists of National Institute of Standards and Technology Lightweight Cryptography standardisation project. Romulus‐M is provably secure, that is, there is a theorem statement showing the upper bound on the success probability of attacking the scheme as a function of adversaries' resources. If there exists an attack that matches the provable security bound, then this implies that the attack is optimal and that the bound is tight in the sense that it cannot be improved. It is shown that the security bounds of Romulus‐M are tight for a large class of parameters by presenting concrete matching attacks.

Read the paper · More papers on PaperTik