Elektrine lite

← Feed

@CryptoOrrDun@ioc.exchange

Post #4239942

2026-07-29 08:40 UTC

@SteveBellovin@infosec.exchange @cryptomancer The short answer: They improve an attack from 2013 (Derbez et al.), based on our improvement from 2010, of an attack by Demirci and Selcuk. They save a byte guessing in a very innovative way, but I am not sure that the true gain is x200 to x800 (or more precisely, I am sure that the ALGORITHMIC gain is not that big, but as they can access smaller tables, then it may be faster in real life).

Replies (1)

  • From what I understand, they attacked a 7 round version of #AES and not the standardised 10 rounds for AES-128, no? If so, would the attack scale to the 14 rounds of AES-256? CC: @SteveBellovin@infosec.exchange @CryptoOrrDun@ioc.exchange

    Open ##4239941