A practical forgery and state recovery attack on the authenticated cipher PANDA-s.

Xiutao Feng,Fan Zhang,Hui Wang
2014-01-01
Abstract:PANDA is a family of authenticated ciphers submitted to CARSAR, which consists of two ciphers: PANDA-s and PANDA-b. In this work we present a state recovery attack against PANDA-s with time complexity about 2 under the known-plaintext-attack model, which needs about 132 pairs of known plaintext/ciphertext. Based on the above attack, we further deduce a forgery attack against PANDA-s. Our results show that PANDA-s is far from the goal of its security design (128-bit level).
What problem does this paper attempt to address?