By Dmitry Khovratovich, Ivica Nikolić, Christian Rechberger (auth.), Masayuki Abe (eds.)

This ebook constitutes the refereed court cases of the sixteenth overseas convention at the concept and alertness of Cryptology and knowledge safety, ASIACRYPT 2010, held in Singapore, in December 2010. The 35 revised complete papers awarded have been conscientiously reviewed and chosen from 216 submissions. The papers are equipped in topical sections on hash assaults; symmetric-key cryptosystems; block and circulation ciphers; protocols; key trade; starting place; zero-knowledge; lattice-based cryptography; safe communique and computation; types, notions, and assumptions; and public-key encryption.

TNeq −1 of the compression function is then an aﬃne function of the variables. Compute the coeﬃcients of this function (step 8). – Solve the resulting system of aﬃne equations (step 9). If it does not have any solution, start again. – If the linear system has a solution mi , Ci , compute the compression function to determine whether F (Ci , mi ) = C ∗ (step 10). This occurs with probability 2Neq −256 . If not, start again. 1 Building and Solving the Equation Systems A basic idea. The ﬁrst idea to compute the coeﬃcients of the equation system would be to reuse the idea of Section 3.

Choose the Constant bits of the chaining variable, and the message block m such that all the conditions are veriﬁed. 3. Choose a set of 8 auxiliary variables such that the resulting auxiliary conditions are veriﬁed. For a random value of the initial internal state, we can ﬁnd 8 auxiliary variables with a good probability. If not so, go back to step 2. 4. Compute the ﬁrst two rounds of the compression function with all the Variables and auxiliary variables set to 0. Keep trace of the results of internal operations.

We then study the propagation of these variables through the compression function. The propagation is not always deterministic - it is probabilistic through the S-box layers. For each intermediate bit of the internal state, we then determine if it is independent from z and z , if it can depend linearly on z and/or z or if it can be quadratic in z and z . The diﬀusion layer L is linear. Therefore a bit of the internal state after the diﬀusion layer is always aﬃne in z, z if and only if all the input bits it depends on also are always aﬃne in z, z .

