{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,27]],"date-time":"2026-01-27T11:32:43Z","timestamp":1769513563509,"version":"3.49.0"},"reference-count":0,"publisher":"Universitatsbibliothek der Ruhr-Universitat Bochum","issue":"2","license":[{"start":{"date-parts":[[2024,6,18]],"date-time":"2024-06-18T00:00:00Z","timestamp":1718668800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ToSC"],"abstract":"<jats:p>The best-known distinguisher on 7-round Ascon-128 and Ascon-128a AEAD uses a 60-dimensional cube where the nonce bits are set to be equal in the third and fourth rows of the Ascon state during initialization (Rohit et al. ToSC 2021\/1). It was not known how to use this distinguisher to mount key-recovery attacks. In this paper, we investigate this problem using a new strategy called break-fix for the conditional cube attack. The idea is to introduce slightly-modified cubes which increase the degrees of 7-round output bits to be more than 59 (break phase) and then find key conditions which can bring the degree back to 59 (fix phase). Using this idea, key-recovery attacks on 7-round Ascon-128, Ascon-128a and Ascon-80pq are proposed. The attacks have better time\/memory complexities than the existing attacks, and in some cases improve the weak-key attacks as well.<\/jats:p>","DOI":"10.46586\/tosc.v2024.i2.118-140","type":"journal-article","created":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T14:36:29Z","timestamp":1718807789000},"page":"118-140","source":"Crossref","is-referenced-by-count":4,"title":["Improved Conditional Cube Attacks on Ascon AEADs in Nonce-Respecting Settings"],"prefix":"10.46586","volume":"2024","author":[{"given":"Kai","family":"Hu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"25480","published-online":{"date-parts":[[2024,6,18]]},"container-title":["IACR Transactions on Symmetric Cryptology"],"original-title":[],"link":[{"URL":"https:\/\/tosc.iacr.org\/index.php\/ToSC\/article\/download\/11623\/11114","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/tosc.iacr.org\/index.php\/ToSC\/article\/download\/11623\/11114","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T14:36:29Z","timestamp":1718807789000},"score":1,"resource":{"primary":{"URL":"https:\/\/tosc.iacr.org\/index.php\/ToSC\/article\/view\/11623"}},"subtitle":["with a Break-Fix Strategy"],"short-title":[],"issued":{"date-parts":[[2024,6,18]]},"references-count":0,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2024,6,18]]}},"URL":"https:\/\/doi.org\/10.46586\/tosc.v2024.i2.118-140","relation":{},"ISSN":["2519-173X"],"issn-type":[{"value":"2519-173X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6,18]]}}}