Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This bias testing is essentially ruling out candidates with very high probability truncated differentials of Hamming weight 1. In a cryptographic primitive you want to rule out _all_ high-probability differentials, which requires different methods. You also want to rule out other high-probability statistical distinguishing properties, such as linear approximations, higher-order differentials, etc.

That being said, this sort of quick-and-dirty testing is useful to filter out obviously bad candidates at the early design phase of, say, an ARX primitive.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: