• DocumentCode
    43478
  • Title

    On the Influence of the Algebraic Degree of F^{-1} on the Algebraic Degree of G \\circ F

  • Author

    Boura, Christina ; Canteaut, Anne

  • Author_Institution
    SECRET Project-Team, INRIA Paris-Rocquencourt, Le Chesnay, France
  • Volume
    59
  • Issue
    1
  • fYear
    2013
  • fDate
    Jan. 2013
  • Firstpage
    691
  • Lastpage
    702
  • Abstract
    We present a study on the algebraic degree of iterated permutations seen as multivariate polynomials. The main result shows that this degree depends on the algebraic degree of the inverse of the permutation which is iterated. This result is also extended to noninjective balanced vectorial functions where the relevant quantity is the minimal degree of the inverse of a permutation expanding the function. This property has consequences in symmetric cryptography since several attacks or distinguishers exploit a low algebraic degree, like higher order differential attacks, cube attacks, and cube testers, or algebraic attacks. Here, we present some applications of this improved bound to a higher degree variant of the block cipher KN, to the block cipher Rijndael-256 and to the inner permutations of the hash functions ECHO and JH.
  • Keywords
    cryptography; polynomials; algebraic attack; algebraic degree; block cipher Rijndael-256; cube attack; cube tester; hash function ECHO; hash function JH; higher order differential attack; iterated permutation; multivariate polynomial; noninjective balanced vectorial function; symmetric cryptography; Boolean functions; Frequency modulation; Gold; Polynomials; Vectors; Algebraic degree; block ciphers; hash functions; higher order differential attacks;
  • fLanguage
    English
  • Journal_Title
    Information Theory, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9448
  • Type

    jour

  • DOI
    10.1109/TIT.2012.2214203
  • Filename
    6303910