A Univariate Attack Against the Limited-Data Instance of Ciminion
摘要
With the increasing interest for advanced protocols for Multi-Party Computation, Fully-Homomorphic Encryption or Zero-Knowledge proofs, a need for cryptographic algorithms with new constraints has emerged. These algorithms, called Arithmetization-Oriented ciphers, seek to minimize the number of field multiplications in large finite fields \(\mathbb {F}_{2^n}\) or \(\mathbb {F}_{p}\) . Among them, Ciminion is an encryption algorithm proposed by Dobraunig et al. at Eurocrypt 2021. In this paper, we focus on the limited-data instance of Ciminion; the parameters of this instance were chosen to provide s-bit security against an attacker that has access to at most \(2^{s/2}\) data. We present a new univariate modeling of Ciminion and show that the designers choice to reduce the number of rounds under this data constraint leads to full-round attacks for security levels \(s\ge 93\) . We also propose some slight modifications of Ciminion that would overcome this vulnerability.