

{"id":86,"date":"2020-11-10T18:16:30","date_gmt":"2020-11-10T17:16:30","guid":{"rendered":"https:\/\/project.inria.fr\/saturnin\/?page_id=86"},"modified":"2020-11-10T18:16:30","modified_gmt":"2020-11-10T17:16:30","slug":"challenge","status":"publish","type":"page","link":"https:\/\/project.inria.fr\/saturnin\/challenge\/","title":{"rendered":"Challenge"},"content":{"rendered":"<p><\/p>\n<div id=\"magicdomid16\" class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">If Saturnin makes <\/span><span class=\"author-a-gez81zz77zz68z9z68zke0lhz70ztxw\">it<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\"> to the third <\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\">round of the NIST lightweight cryptography process<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">, we would like to add to our submission <\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">a QCB version of Saturnin: Saturnin-QCB, combining this <a href=\"https:\/\/eprint.iacr.org\/2020\/1304\">newly proposed mode<\/a>\u00a0 <a href=\"https:\/\/eprint.iacr.org\/2020\/1304.pdf\">[pdf]<\/a> with the 16<\/span><span class=\"author-a-z78zz67zz68zaz82zz66zf7v31z67zz88zz83za4\"> Super-<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">round version of Saturnin.<\/span><\/div>\n<div id=\"magicdomid18\" class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">As this version uses a tweak added to the key, related-key security\u00a0<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">seems particularly relevant in this scenario.<\/span><\/div>\n<div>\n<div id=\"magicdomid26\" class=\"ace-line\"><\/div>\n<\/div>\n<div id=\"magicdomid21\" class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">To<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\"> encourage third-party <\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">related-key <\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\">cryptanalysis<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\"> on round-reduced versions of <\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">the Saturnin instances used in this new proposal, we launch the following challenges, detailed below.<\/span><\/div>\n<div id=\"magicdomid24\" class=\"ace-line\"><\/div>\n<div id=\"magicdomid25\" class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">The teams proposing the first results in each category will be the winners of a batch of typical <\/span><span class=\"author-a-z78zz67zz68zaz82zz66zf7v31z67zz88zz83za4\">F<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">rench and duck-related pri<\/span><span class=\"author-a-z65zhz77z4ynz69zz84zrz68zz76zz80zz87zyz80zz86z\">z<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">es,\u00a0<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">that will depend on the challenge solved. These pri<\/span><span class=\"author-a-z65zhz77z4ynz69zz84zrz68zz76zz80zz87zyz80zz86z\">z<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">es will be awarded at the end of March 2021.\u00a0<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\"> Please send us your results if you want to take part in the challenge to the following address:<\/span><\/div>\n<div>maria.naya_plasencia \\at\\ inria.fr.<\/div>\n<div id=\"magicdomid30\" class=\"ace-line\"><\/div>\n<div id=\"magicdomid31\" class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">Both classical and quantum attacks are accepted.<\/span><\/div>\n<div id=\"magicdomid32\" class=\"ace-line\"><\/div>\n<div id=\"magicdomid34\" class=\"ace-line\"><\/div>\n<h4 id=\"magicdomid35\" class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">Category 1:\u00a0 <\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">related-key attacks on reduced-round Saturnin<\/span><\/h4>\n<div class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">Our best attack, that can be found in <a href=\"https:\/\/project.inria.fr\/saturnin\/note-rk-2\/\">the following note<\/a>, reaches up to 10 rounds cla<\/span><span class=\"author-a-z78zz67zz68zaz82zz66zf7v31z67zz88zz83za4\">s<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">sically.<\/span><\/div>\n<div><\/div>\n<table>\n<tbody>\n<tr>\n<th>Rounds<\/th>\n<td>10<\/td>\n<td>11<\/td>\n<td>12<\/td>\n<td>13<\/td>\n<td>14<\/td>\n<td>15<\/td>\n<td>16<\/td>\n<\/tr>\n<tr>\n<th>Authors<\/th>\n<td>Saturnin team<\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<th>Complexity<\/th>\n<td>2<sup>236<\/sup> (classical)<\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div><\/div>\n<div><\/div>\n<div><\/div>\n<div><\/div>\n<h4 id=\"magicdomid38\" class=\"ace-line\"><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\">Category <\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">2<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\">: Saturnin-QCB<\/span><\/h4>\n<div id=\"magicdomid40\" class=\"ace-line\">\n<div id=\"magicdomid39\" class=\"ace-line\"><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">P<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\">rize<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">s<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\"> will<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\"> also<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\"> be<\/span> <span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\">awarded to the best cryptanalysis result<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">s<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\"> (number of rounds, practicality) against Saturnin-QCB. For these attacks, the IV can be either adversary-controlled<\/span><span class=\"author-a-z65zhz77z4ynz69zz84zrz68zz76zz80zz87zyz80zz86z\">,<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\"> or random<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\"> (<\/span><span class=\"author-a-z65zhz77z4ynz69zz84zrz68zz76zz80zz87zyz80zz86z\">the latter being the most difficult, and thus the most interesting<\/span><span class=\"author-a-tdnz78z4kmc6z89z4bz90zz87zrz72z\">)<\/span><span class=\"author-a-z79zvz80zz66zgsz71zt0v8xz74zz80zz89zb\">.<\/span><\/div>\n<\/div>\n<div><\/div>\n<div>\n<table>\n<tbody>\n<tr>\n<th>Rounds<\/th>\n<td>9<\/td>\n<td>10<\/td>\n<td>11<\/td>\n<td>12<\/td>\n<td>13<\/td>\n<td>14<\/td>\n<td>15<\/td>\n<td>16<\/td>\n<\/tr>\n<tr>\n<th>Authors<\/th>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<th>Complexity<\/th>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div><\/div>\n<\/div>\n<div><\/div>\n<div><\/div>\n<div id=\"magicdomid41\" class=\"ace-line\"><\/div>\n<div><\/div>\n<p><\/p>","protected":false},"excerpt":{"rendered":"<p>If Saturnin makes it to the third round of the NIST lightweight cryptography process, we would like to add to our submission a QCB version of Saturnin: Saturnin-QCB, combining this newly proposed mode\u00a0 [pdf] with the 16 Super-round version of Saturnin. As this version uses a tweak added to the\u2026<\/p>\n<p> <a class=\"continue-reading-link\" href=\"https:\/\/project.inria.fr\/saturnin\/challenge\/\"><span>Continue reading<\/span><i class=\"crycon-right-dir\"><\/i><\/a> <\/p>\n","protected":false},"author":1367,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-86","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/pages\/86","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/users\/1367"}],"replies":[{"embeddable":true,"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/comments?post=86"}],"version-history":[{"count":27,"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/pages\/86\/revisions"}],"predecessor-version":[{"id":136,"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/pages\/86\/revisions\/136"}],"wp:attachment":[{"href":"https:\/\/project.inria.fr\/saturnin\/wp-json\/wp\/v2\/media?parent=86"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}