This shows you the differences between two versions of the page.
Next revision Both sides next revision | |||
paes [17/03/2014 12:37:26] mmeh created |
paes [21/03/2014 08:02:33] mmeh [Cryptanalysis] |
||
---|---|---|---|
Line 6: | Line 6: | ||
===== Cryptanalysis ===== | ===== Cryptanalysis ===== | ||
+ | Jérémy Jean and Ivica Nikolić describe a distinguisher for PAES in [[http://www1.spms.ntu.edu.sg/~syllab/m/images/6/6e/Using_AES_Round_Symmetries_to_Distinguish_PAES.pdf|this note]]. Independently, Markku-Juhani O. Saarinen reports issues with rotational invariants in PAES in [[https://groups.google.com/forum/#!topic/crypto-competitions/vRmJdRQBzOo|this thread]] that lead to distinguishing and key-recovery shortcuts. |