{"entities":{"Q7015302":{"pageid":21594735,"ns":120,"title":"Item:Q7015302","lastrevid":78410483,"modified":"2026-05-06T11:31:40Z","type":"item","id":"Q7015302","labels":{"en":{"language":"en","value":"Algebraic cryptanalysis of Ascon using MRHS equations"}},"descriptions":{"en":{"language":"en","value":"scientific article; zbMATH DE number 8008485"}},"aliases":{},"claims":{"P31":[{"mainsnak":{"snaktype":"value","property":"P31","hash":"fd5912e4dab4b881a8eb0eb27e7893fef55176ad","datavalue":{"value":{"entity-type":"item","numeric-id":56887,"id":"Q56887"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$47892B2A-648E-4F2F-8DC7-CCB78A24D090","rank":"normal"}],"P159":[{"mainsnak":{"snaktype":"value","property":"P159","hash":"fe60b96a475fe923865d7b45436b08df1344d22b","datavalue":{"value":{"text":"Algebraic cryptanalysis of Ascon using MRHS equations","language":"en"},"type":"monolingualtext"},"datatype":"monolingualtext"},"type":"statement","id":"Q7015302$9DA73421-DBC9-4A80-9E04-0D5E8F43AE84","rank":"normal"}],"P225":[{"mainsnak":{"snaktype":"value","property":"P225","hash":"dc776a4058c044357e86662a36611fba0c8fd0ce","datavalue":{"value":"1559.94039","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q7015302$56C0C594-E58A-44AC-BA35-2E8BA2DDC114","rank":"normal"}],"P27":[{"mainsnak":{"snaktype":"value","property":"P27","hash":"63ad6309bd8dce1003f2366e474687a3d4787ed0","datavalue":{"value":"10.2478/TMMP-2024-0007","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q7015302$E78EA37B-F6AB-4802-8244-9A7324A711F3","rank":"normal"}],"P16":[{"mainsnak":{"snaktype":"value","property":"P16","hash":"52e8cebef3ef8dc6e3af3c54f45b7468e9953361","datavalue":{"value":{"entity-type":"item","numeric-id":7015301,"id":"Q7015301"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$30FD2EB8-7651-4F18-AFBC-2460F016A776","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P16","hash":"8a9bcb5564a7e76a6a62cffa78830d30fe4b603d","datavalue":{"value":{"entity-type":"item","numeric-id":510447,"id":"Q510447"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$B1C9DA00-C930-4143-9D37-AB6CB3E60B81","rank":"normal"}],"P200":[{"mainsnak":{"snaktype":"value","property":"P200","hash":"d2f2f8d99efc72d8c8774c973e07c89a0c8e48e3","datavalue":{"value":{"entity-type":"item","numeric-id":2057282,"id":"Q2057282"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$023E0AC8-E438-4970-993B-97DA94A1E2AB","rank":"normal"}],"P28":[{"mainsnak":{"snaktype":"value","property":"P28","hash":"2c69184b979e9d5254d4001e4d4729c42795ce2f","datavalue":{"value":{"time":"+2025-03-10T00:00:00Z","timezone":0,"before":0,"after":0,"precision":11,"calendarmodel":"http://www.wikidata.org/entity/Q1985727"},"type":"time"},"datatype":"time"},"type":"statement","id":"Q7015302$E56BF9E3-00A6-4F2B-BAA0-CC393FC278B2","rank":"normal"}],"P1448":[{"mainsnak":{"snaktype":"value","property":"P1448","hash":"849214377b6acc5e37e96409d37161c7324eb35e","datavalue":{"value":"Ascon, a finalist in the NIST Lightweight Cryptography competition, is a family of lightweight authenticated encryption and hashing algorithms. This paper focuses on providing cryptanalytic results from an algebraic point of view. More precisely, the authors use the multiple right-hand sides (MRHS) representation to analyze the security of Ascon. The paper aims to gain insight into the security of Ascon, and thus the authors take into consideration different scaled-down versions of the cipher i.e. preserving most of Ascon's cryptographic properties but with a smaller state).\\N\\NThe MRHS analysis is conducted using two solvers: the RZ solver (based on a combination of linear algebra and exhaustive search) and the HC solver (based on adaptive bit-flipping with restarts). Since algebraic problems can have different representations, the authors also consider gate-level representation (where the S-box is represented with AND gates) and S-box-level representation (where the whole S-box is treated as a non-linear element).\\N\\NThe experiments presented in the paper show that Ascon with a single round permutation is vulnerable in a practical multi-block setting, but increasing the number of rounds significantly raises attack complexity, approaching that of an exhaustive search. An important result regarding Ascon is that scaled-down versions can be used to estimate attack complexity trends in MRHS cryptanalysis, providing insights into cipher security while reducing computational costs. Note that even if the MRHS cryptanalysis does not detect any flaws, that does not necessarily mean the cipher is safe from other attacks.\\N\\NWhen applied to structured systems like Ascon, the RZ solver is faster than the HC solver. More precisely, in the initial experiments, the authors used 8 S-boxes and one round and found that the RZ solver was successful in 0.01 seconds, while the HC solver could not solve some instances even in 100 seconds (the stopping threshold for the HC algorithm). While the RZ solver is highly efficient for structured systems like Ascon, the HC solver performs comparably to the RZ solver when applied to random MRHS systems. Although the HC solver underperformed for structured systems, this may be because it is a prototype, and thus more research is needed to tune it better.\\N\\NRegarding the algebraic representation, the RZ solver using the S-box representation is more computationally efficient than the one using the gate-level representation. On the other hand, the HC solver had similar results for both representations (i.e. similar probability in fixed time). The only gap is when random systems are considered, the HC solver benefiting from gate-level representation i.e. higher probability in fixed time).\\N\\NRegarding the algebraic representation, the RZ solver using the S-box representation is more computationally efficient than the one using the gate-level representation. On the other hand, the HC solver had similar results for both representations i.e. similar solving probability within a fixed time limit). For random MRHS systems and Ascon-bases systems with a larger number of unknowns, the HC solver performs better with the gate-level representation i.e. higher solving probability within a fixed time limit).","type":"string"},"datatype":"string"},"type":"statement","id":"Q7015302$DC90A544-F3CA-4FC2-9C53-48B6381A0BF6","rank":"normal"}],"P1447":[{"mainsnak":{"snaktype":"value","property":"P1447","hash":"20384534bc0ed89c8fd9c478e770df26c9e2ddfc","datavalue":{"value":{"entity-type":"item","numeric-id":2151282,"id":"Q2151282"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$60BCAE0B-70E4-4000-AEA8-F7F73B1B6416","rank":"normal"}],"P226":[{"mainsnak":{"snaktype":"value","property":"P226","hash":"b3f5570531d36cdad95fcc8cba24a2dabc5fbbbf","datavalue":{"value":"94A60","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q7015302$5C674592-57E0-4BF2-9F34-EC6BD65666CB","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P226","hash":"332a7ca0fc2503044cbe5299ecaa975484163791","datavalue":{"value":"14G50","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q7015302$6163DB67-E1EA-4D8A-9170-F63EC42985F6","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P226","hash":"58bd804a9b32ab16fea71636cf187b83a20de8f7","datavalue":{"value":"68P25","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q7015302$3F6EA7B1-40F0-4764-9536-AF963B1DBB2B","rank":"normal"}],"P1451":[{"mainsnak":{"snaktype":"value","property":"P1451","hash":"bdd04db9138616bc70f4e6ec3c26bb1d385863cb","datavalue":{"value":"8008485","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q7015302$6D58F71F-BAE2-44EC-9F1A-A060136C6770","rank":"normal"}],"P163":[{"mainsnak":{"snaktype":"value","property":"P163","hash":"c39a117a349789e54237c0a3254f5a10c0a6517e","datavalue":{"value":{"entity-type":"item","numeric-id":6830565,"id":"Q6830565"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$300E482B-B646-49FD-A35C-28B93993BCB8","rank":"normal"}],"P1450":[{"mainsnak":{"snaktype":"value","property":"P1450","hash":"c5e3c1ccfcd074ce8ffe37d61b99d67758426759","datavalue":{"value":"algebraic cryptanalysis","type":"string"},"datatype":"string"},"type":"statement","id":"Q7015302$ECC6D8CC-BC67-44C6-A9F3-06D3A47AD5B0","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1450","hash":"0799b2d70d995f3244795060a50ebedb7f829b08","datavalue":{"value":"MRHS equations","type":"string"},"datatype":"string"},"type":"statement","id":"Q7015302$FA4A2813-B7AB-493C-94C4-413DE8477A54","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1450","hash":"c920ce0e73af37aa4fe6a3f6ecc7439c0e1f6e44","datavalue":{"value":"Ascon cipher","type":"string"},"datatype":"string"},"type":"statement","id":"Q7015302$AF397A13-3BD2-4C3C-90E4-01E46B60C3F6","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1450","hash":"4c357ad85f5e54f8d971d82ec04e42a246af1329","datavalue":{"value":"lightweight cryptography","type":"string"},"datatype":"string"},"type":"statement","id":"Q7015302$30C0A3CA-E7E6-4668-8234-D9827119A7B8","rank":"normal"}],"P1460":[{"mainsnak":{"snaktype":"value","property":"P1460","hash":"57f7fea50d2ce1b39b695c4a1313582eed405e38","datavalue":{"value":{"entity-type":"item","numeric-id":5976449,"id":"Q5976449"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$0521FCC8-88E1-4641-95A2-331F352D614D","rank":"normal"}],"P223":[{"mainsnak":{"snaktype":"value","property":"P223","hash":"567a812e96955258dd73ed37a6cc1215cf6e20d2","datavalue":{"value":{"entity-type":"item","numeric-id":3532870,"id":"Q3532870"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$13FA8366-60C8-4FE9-9100-1FF0887A8527","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"e01ba75f44d99ac03fed4a3a414e3d7034ad0ff9","datavalue":{"value":{"entity-type":"item","numeric-id":2760977,"id":"Q2760977"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$445230DD-1AD9-466D-8D6C-DFBB11BBACF6","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"5b68011a4b7d2070df472bf5689c9c3d0d24a8fe","datavalue":{"value":{"entity-type":"item","numeric-id":2044758,"id":"Q2044758"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$39E5B4AC-DFBC-47E0-819D-2B770F2A302F","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"b7a8036e4e03de2c4cc183b120f4794fa24c75cc","datavalue":{"value":{"entity-type":"item","numeric-id":5452259,"id":"Q5452259"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$D20381B8-FAE7-4332-8F90-F885852D3CD9","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"47207f21523390e91c5c58ba036d38dd3455c99d","datavalue":{"value":{"entity-type":"item","numeric-id":1009068,"id":"Q1009068"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$1707E45C-EADE-40A2-AFA1-0C82091F1576","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"e8e14aaa7add143429f7fc94b2ce3742eb06a7d7","datavalue":{"value":{"entity-type":"item","numeric-id":1787192,"id":"Q1787192"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$9A53163C-9538-4015-999C-8D654966CE86","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"a385c7d7e95e1db1030e99a9f94daf12802820a8","datavalue":{"value":{"entity-type":"item","numeric-id":2873166,"id":"Q2873166"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$025A4EE4-D28F-4F18-A9CD-C0AEB09F0BC1","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"40887a7594e85e9b06675ee9754efded1975e5e8","datavalue":{"value":{"entity-type":"item","numeric-id":2970278,"id":"Q2970278"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$F6D1D303-0814-475B-84D0-A2CCC847D72C","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"eac6b29bc54d28c5af66016cf1e4061ee2048bcb","datavalue":{"value":{"entity-type":"item","numeric-id":4606490,"id":"Q4606490"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$AECAD0AE-4919-431B-961C-6789E0CAE362","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"b1923b4ff58741765292dd6900561e4dbf432e5a","datavalue":{"value":{"entity-type":"item","numeric-id":5145714,"id":"Q5145714"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$9D9A74C1-3505-419E-82D8-EB2B7338CFEE","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P223","hash":"20f1dcdb0203c9df17ef6dd1b5c5c192c7c5715e","datavalue":{"value":{"entity-type":"item","numeric-id":5886165,"id":"Q5886165"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q7015302$291E5B6A-09BB-4684-B0B0-0BA804B69C67","rank":"normal"}]},"sitelinks":{"mardi":{"site":"mardi","title":"Algebraic cryptanalysis of Ascon using MRHS equations","badges":[],"url":"https://portal.mardi4nfdi.de/wiki/Algebraic_cryptanalysis_of_Ascon_using_MRHS_equations"}}}}}