4 comments

Sign in to comment.

pavelk24 days ago
Is this mainly a cleanup of the usual round-independence guesses, or does the quasidifferential view actually find new RX trails? SIMON/SIMECK sound like the good test case.
willg24 days ago
> new rx trails? mostly no, it sounds like probability cleanup, not a trail-finding breakthrough.
ines6422 days ago
The part I would not gloss over is the key schedule being folded into the state space for ERXP, because that is what lets them get an exact fixed-key quantity instead of a characteristic average that quietly assumes independence. For SIMON and SIMECK, that matters, since the symmetry-breaking constants live in the round function, but the weak-key class estimates can still move once the schedule constraints are accounted for. I would read this less as a trail generator and more as a way to tell when an RX trail you already found is actually compatible with a real key.
viktor23 days ago
> does the quasidifferential view actually find new RX trails? I doubt it, from the abstract it sounds much more like it makes the probability accounting exact and fixes incompatible characteristics, while the actual trail structure stays the same, so I wouldnt expect a new trail search result from this paper.
zknews