### Abstract

We describe an approach to zero-sum partitions using Todo's division property at EUROCRYPT 2015. It follows the inside-out methodology, and includes MILP-assisted search for the forward and backward trails, and subspace approach to connect those two trails that is less restrictive than commonly done.As an application we choose PHOTON, a family of sponge-like hash function proposals that was recently standardized by ISO. With respect to the security claims made by the designers, we for the first time show zero-sum partitions for almost all of those full 12-round permutation variants that use a 4-bit S-Box. As with essentially any other zero-sum property in the literature, also here the gap between a generic attack and the shortcut is small.

Original language | English |
---|---|

Title of host publication | Topics in Cryptology – CT-RSA 2018 |

Editors | Nigel P. Smart |

Number of pages | 21 |

Volume | 10808 |

Publisher | Springer |

Publication date | 2018 |

Pages | 279-299 |

ISBN (Print) | 978-3-319-76952-3 |

ISBN (Electronic) | 978-3-319-7693-0 |

DOIs | |

Publication status | Published - 2018 |

Event | RSA Conference 2018 - San Fancisco, United States Duration: 16 Apr 2018 → 20 Apr 2018 |

### Conference

Conference | RSA Conference 2018 |
---|---|

Country | United States |

City | San Fancisco |

Period | 16/04/2018 → 20/04/2018 |

Series | Lecture Notes in Computer Science |
---|---|

ISSN | 0302-9743 |

### Keywords

- PHOTON
- Integral
- Division property
- Zero-sum MILP
- Subspace

## Cite this

Wang, Q., Grassi, L., & Rechberger, C. (2018). Zero-Sum Partitions of PHOTON Permutations. In N. P. S. (Ed.),

*Topics in Cryptology – CT-RSA 2018*(Vol. 10808, pp. 279-299). Springer. Lecture Notes in Computer Science https://doi.org/10.1007/978-3-319-76953-0_15