This is an old revision of the document!
Type | Number of Queries | Computations | Reference | Comment |
---|---|---|---|---|
Forgery | $2^{11}$ | $2^{11}$ | Yu Sasaki and Lei Wang1) |
Jérémy Jean and Ivica Nikolić describe a distinguisher for PAES in this note. Independently, Markku-Juhani O. Saarinen reports issues with rotational invariants in PAES in this thread that lead to distinguishing and key-recovery shortcuts.