This is an old revision of the document!
|Type||Number of Queries||Computations||Reference||Comment|
|Forgery||2 pow 11||2 pow 11||Yu Sasaki and Lei Wang1)|
Jérémy Jean and Ivica Nikolić describe a distinguisher for PAES in this note. Independently, Markku-Juhani O. Saarinen reports issues with rotational invariants in PAES in this thread that lead to distinguishing and key-recovery shortcuts.