标题：New Distinguisher on Reduced-Round Keccak Sponge Function
作者：Huang, Senyang; Wang, Xiaoyun; Xu, Guangwu; Wang, Meiqin; Zhao, Jingyuan
作者机构：[Huang, Senyang; Wang, Xiaoyun] Tsinghua Univ, Inst Adv Study, Beijing 100084, Peoples R China.; [Huang, Senyang] Univ Haifa, Dept Comp Sci, IL-3498 更多
通讯作者：Huang, SY;Huang, SY
通讯作者地址：[Huang, SY]Tsinghua Univ, Inst Adv Study, Beijing 100084, Peoples R China;[Huang, SY]Univ Haifa, Dept Comp Sci, IL-3498838 Haifa, Israel.
来源：IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES
关键词：Keccak sponge function; conditional cube tester; conditional cube; variable; ordinary cube variable
摘要：The security analysis of Keccak, the winner of SHA-3, has attracted considerable interest. Recently, some attention has been paid to distinguishing Keccak sponge function from random permutation. In EUROCRYPT'17, Huang et al. proposed conditional cube tester to recover the key of Keccak-MAC and Keyak and to construct practical distinguishing attacks on Keccak sponge function up to 7 rounds. In this paper, we improve the conditional cube tester model by refining the formulation of cube variables. By classifying cube variables into three different types and working the candidates of these types of cube variable carefully, we are able to establish a new theoretical distinguisher on 8-round Keccak sponge function. Our result is more efficient and greatly improves the existing results. Finally we remark that our distinguishing attack on the the reduced-round Keccak will not threat the security margin of the Keccak sponge function.