Note on Zero-sum Distinguishers of Kkkkkk-f 2 a Generic Method


introduced zero-sum distinguish-ers, a method to generate zero-sum structures for reduced-round KKKKKK-f [1600], the permutation underlying our SHA-3 submission KKKKKK. Their paper contained distinguishers for up to 16 rounds of KKKKKK-f [1600]. Recently, Christina Boura and Anne Canteaut extended this to 18 rounds in [6]. In this note we argue that the… (More)

