Jian Guo

From ESC2017
Title: S-box Linearization: Applications to Collision and Preimage Attacks of Round-Reduced Keccak

Abstract: The chi operation plays the role of the only non-linear layer of Keccak round function. Due to its low algebraic degree, linearization is possible when the input is restricted to some input subsets. In this talk, we show how this idea can be extended to the best up-to-date collision and preimage attacks against round-reduced Keccak.