[Resource Topic] 2023/963: An invariant of the round function of QARMAv2-64

Authors: Tim Beyne


This note shows that there exists a nontrivial invariant for the unkeyed round function of QARMAv2-64. It is invariant under translation by a set of 2^{32} constants. The invariant does not extend over all rounds of QARMAv2-64 and probably does not lead to full-round attacks. Nevertheless, it might be of interest as it can be expected to give meaningful weak-key attacks on round-reduced instances when combined with other techniques such as integral cryptanalysis.

ePrint: https://eprint.iacr.org/2023/963

