@inproceedings{37b01f5ee89e4fb88e5e0a7fc71e0428,

title = "Zero-Sum Partitions of PHOTON Permutations",

abstract = "We describe an approach to zero-sum partitions using Todo's division property at EUROCRYPT 2015. It follows the inside-out methodology, and includes MILP-assisted search for the forward and backward trails, and subspace approach to connect those two trails that is less restrictive than commonly done.As an application we choose PHOTON, a family of sponge-like hash function proposals that was recently standardized by ISO. With respect to the security claims made by the designers, we for the first time show zero-sum partitions for almost all of those full 12-round permutation variants that use a 4-bit S-Box. As with essentially any other zero-sum property in the literature, also here the gap between a generic attack and the shortcut is small.",

keywords = "PHOTON, Integral, Division property, Zero-sum MILP, Subspace",

author = "Qingju Wang and Lorenzo Grassi and Christian Rechberger",

year = "2018",

doi = "10.1007/978-3-319-76953-0_15",

language = "English",

isbn = "978-3-319-76952-3",

volume = "10808",

series = "Lecture Notes in Computer Science",

publisher = "Springer",

pages = "279--299",

editor = "{Nigel P. Smart}",

booktitle = "Topics in Cryptology – CT-RSA 2018",

note = "RSA Conference 2018 ; Conference date: 16-04-2018 Through 20-04-2018",

}