[Resource Topic] 2019/865: Cryptanalysis of Reduced-Round SipHash

Welcome to the resource topic for 2019/865

Cryptanalysis of Reduced-Round SipHash

Authors: Le He, Hongbo Yu


SipHash is a family of ARX-based MAC algorithms optimized for short inputs. Already, a lot of implementations and applications for SipHash have been proposed, whereas the cryptanalysis of SipHash still lags behind. In this paper, we study the property of truncated differential in SipHash and find out the output bits with the most imbalanced differential biases. Making use of these results, we construct distinguishers with practical complexity 2^{10} for SipHash-2-1 and 2^{36} for SipHash-2-2. We further reveal the relations between the value of output bias and the difference after first modular addition step, which is directly determined by corresponding key bits. Based on these relations, we propose a key recovery method for SipHash-2-1 that can obtain a nonuniform distribution of the 128-bit key through several bias tests. It is found that the highest probability can reach 2^{-41} and the nonuniform distribution can lead to a 2^{29} gain of search cost in average.

ePrint: https://eprint.iacr.org/2019/865

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .