Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Miyaguchi Preneel #42

merged 3 commits into from Sep 8, 2018

Miyaguchi Preneel #42

merged 3 commits into from Sep 8, 2018


Copy link

@HarryR HarryR commented Sep 7, 2018

Fixes #37

@HarryR HarryR merged commit a686fd3 into master Sep 8, 2018
@HarryR HarryR deleted the Miyaguchi-Preneel branch September 8, 2018 07:27
Copy link

@daira daira left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

12 rounds are not even remotely enough. The MiMC paper says you need ceiling(log3(p)) rounds for e = 5 (that's not a typo; definitely log3), and ceiling(log7(p)) rounds for e = 7.

Copy link
Owner Author

HarryR commented Nov 24, 2018

Yup I 100% agree here, 12 rounds are not enough.

On my todo list is to increase it significantly.

There is a very practical attack against 12 rounds which requires only 128gb of RAM.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
None yet
None yet

Successfully merging this pull request may close these issues.

None yet

2 participants