<p><Emphasis FontCategory="NonProportional">SCARF</Emphasis>, an ultra low-latency tweakable block cipher, is the first cipher designed for cache randomization. The block cipher design is significantly different from other common tweakable block ciphers; with a block size of only 10 bits, and yet the input key size is a whopping 240 bits. Notably, the majority of the round key in its round function is absorbed into the data path through AND operations, rather than the typical XOR operations. In this paper, we present a key-recovery attack on a round-reduced version of <Emphasis FontCategory="NonProportional">SCARF</Emphasis> with 4 + 4 rounds under the single pair-of-tweaks setting. Our attack is essentially a Meet-in-the-Middle (MitM) attack, where the matching phase is represented by a system of linear equations. Unlike the cryptanalysis conducted by the designers, our attack is effective under both security requirements they have outlined. The data complexity of our attack is <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1596_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="21" /> </InlineMediaObject> <EquationSource Format="TEX">\(2^{10}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mn>2</mn> <mn>10</mn> </msup> </math></EquationSource> </InlineEquation> plaintexts, with a time complexity of approximately <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1596_Article_IEq2.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(2^{60.63}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mn>2</mn> <mrow> <mn>60.63</mn> </mrow> </msup> </math></EquationSource> </InlineEquation> 4-round of <Emphasis FontCategory="NonProportional">SCARF</Emphasis> encryptions. It is important to note that our attack does not threaten the overall security of <Emphasis FontCategory="NonProportional">SCARF</Emphasis>.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Meet-in-the-middle attack on round-reduced SCARF under single pair-of-tweaks setting

  • Siwei Chen,
  • Kai Hu,
  • Guozhen Liu,
  • Zhongfeng Niu,
  • Quan Quan Tan,
  • Shichang Wang

摘要

SCARF, an ultra low-latency tweakable block cipher, is the first cipher designed for cache randomization. The block cipher design is significantly different from other common tweakable block ciphers; with a block size of only 10 bits, and yet the input key size is a whopping 240 bits. Notably, the majority of the round key in its round function is absorbed into the data path through AND operations, rather than the typical XOR operations. In this paper, we present a key-recovery attack on a round-reduced version of SCARF with 4 + 4 rounds under the single pair-of-tweaks setting. Our attack is essentially a Meet-in-the-Middle (MitM) attack, where the matching phase is represented by a system of linear equations. Unlike the cryptanalysis conducted by the designers, our attack is effective under both security requirements they have outlined. The data complexity of our attack is \(2^{10}\) 2 10 plaintexts, with a time complexity of approximately \(2^{60.63}\) 2 60.63 4-round of SCARF encryptions. It is important to note that our attack does not threaten the overall security of SCARF.