On Impossible and Truncated Distinguishers for IoT-Friendly AEAD Algorithms
Seungjun Baek, Yongjin Jeon, Giyoon Kim, Jongsung Kim · IEEE Internet of Things Journal · 2024
In this article, we propose a methodology for finding impossible differential distinguishers for permutations used in sponge-like constructions. Given the difference between the typical block ciphers and such permutations in terms of key additions, we initiate the construction of an impossible differential trail starting from the middle round. Based on the proposed methodology, we present several new or improved truncated and impossible distinguishers for Ascon, DryGascon, Sycon, and Shamash all of which were submitted to the National Institute of Standards and Technology Lightweight Cryptography project. For the Ascon, we significantly reduce the attack complexity compared to the existing results, and notably this marks the first instance of proposing specific truncated and impossible differential trails for Sycon and Shamash. Finally, we discuss how truncated differential distinguishers, identified using our methodology, enable the key-recovery attacks in weak-key setting. The methodology of this article is significant not only for the ciphers considered but also for the other permutation-based ciphers with similar structures. Given that the target algorithms are suitable for the resource-constrained devices, our results provide new insights into security for the Internet of Things.