Abstract
SCARF is a tweakable block cipher dedicated to cache address randomization, proposed at the USENIX Security conference. It has a 10-bit block, 48-bit tweak, and 240-bit key. SCARF is aggressively optimized to meet the harsh latency constraints of cache address randomization, and uses a dedicated model for its security claim. The full version of SCARF has 8 rounds, and its designers claim security up to 240 queries and 280 computations. In this work we present a distinguisher against 6-round SCARF under the collision model with time and query complexity 230, and a key-recovery attack against the full 8-round SCARF under the encryption-decryption model with 239 queries and time 276.2. As part of the attack, we present a novel method to compute the minimal number of right pairs following a differential characteristic when the input pairs are restricted to a subspace of the domain of the primitive.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of The 44th Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2025 |
| Publisher | Springer |
| Publication date | 2025 |
| Pages | 397–426 |
| ISBN (Print) | 978-3-031-91106-4 |
| ISBN (Electronic) | 978-3-031-91107-1 |
| DOIs | |
| Publication status | Published - 2025 |
| Event | The 44th Annual International Conference on the Theory and Applications of Cryptographic Techniques - Madrid, Spain Duration: 4 May 2025 → 8 May 2025 |
Conference
| Conference | The 44th Annual International Conference on the Theory and Applications of Cryptographic Techniques |
|---|---|
| Country/Territory | Spain |
| City | Madrid |
| Period | 04/05/2025 → 08/05/2025 |
Keywords
- SCARF
- Tweakable block cipher
- Cryptanalysis
Fingerprint
Dive into the research topics of 'Cryptanalysis of Full SCARF'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver