<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-07-20T14:34:38Z</responseDate>
  <request identifier="1944" metadataPrefix="oai_dc" verb="GetRecord">https://drops.dagstuhl.de/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:drops-oai.dagstuhl.de:1944</identifier>
        <datestamp>2024-03-06T11:08:30Z</datestamp>
        <setSpec>ddc:004</setSpec>
        <setSpec>open_access</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>Cube Testers and Key Recovery Attacks On Reduced-Round MD6 and Trivium</dc:title>
          <dc:creator>Aumasson, Jean-Philippe</dc:creator>
          <dc:creator>Dinur, Itai</dc:creator>
          <dc:creator>Meier, Willi</dc:creator>
          <dc:creator>Shamir, Adi</dc:creator>
          <dc:subject>Cube attacks</dc:subject>
          <dc:subject>property testing</dc:subject>
          <dc:subject>MD6</dc:subject>
          <dc:subject>Trivium</dc:subject>
          <dc:description>CRYPTO 2008 saw the introduction of the hash function&#13;
MD6 and of cube attacks, a type of algebraic attack applicable to cryptographic&#13;
functions having a low-degree algebraic normal form over GF(2).&#13;
This paper applies cube attacks to reduced round MD6, finding the full&#13;
128-bit key of a 14-round MD6 with complexity 2\^22 (which takes less&#13;
than a minute on a single PC). This is the best key recovery attack announced&#13;
so far for MD6. We then introduce a new class of attacks called&#13;
cube testers, based on efficient property-testing algorithms, and apply&#13;
them to MD6 and to the stream cipher Trivium. Unlike the standard&#13;
cube attacks, cube testers detect nonrandom behavior rather than performing&#13;
key extraction, but they can also attack cryptographic schemes&#13;
described by nonrandom polynomials of relatively high degree. Applied&#13;
to MD6, cube testers detect nonrandomness over 18 rounds in 2\^17 complexity;&#13;
applied to a slightly modified version of the MD6 compression&#13;
function, they can distinguish 66 rounds from random in 2\^24 complexity.&#13;
Cube testers give distinguishers on Trivium reduced to 790 rounds from&#13;
random with 2^30 complexity and detect nonrandomness over 885 rounds&#13;
in 2\^27, improving on the original 767-round cube attack.</dc:description>
          <dc:publisher>Schloss Dagstuhl – Leibniz-Zentrum für Informatik</dc:publisher>
          <dc:contributor>Jean-Philippe Aumasson and Itai Dinur and Willi Meier and Adi Shamir</dc:contributor>
          <dc:date>2009</dc:date>
          <dc:relation>Is Part Of Dagstuhl Seminar Proceedings, Volume 9031, Symmetric Cryptography (2009)</dc:relation>
          <dc:type>InProceedings</dc:type>
          <dc:type>Text</dc:type>
          <dc:type>doc-type:ResearchArticle</dc:type>
          <dc:type>publishedVersion</dc:type>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>doi:10.4230/DagSemProc.09031.6</dc:identifier>
          <dc:identifier>urn:nbn:de:0030-drops-19443</dc:identifier>
          <dc:identifier>https://drops.dagstuhl.de/entities/document/10.4230/DagSemProc.09031.6</dc:identifier>
          <dc:language>eng</dc:language>
          <dc:rights>https://creativecommons.org/licenses/by/4.0/legalcode</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
