Indifferentiability with Distinguishers: Why Shabal Does Not Require Ideal Ciphers.
Emmanuel BressonAnne CanteautBenoît Chevallier-MamesChristophe ClavierThomas FuhrAline GougetThomas IcartJean-François MisarskyMaría Naya-PlasenciaPascal PaillierThomas PorninJean-René ReinhardCéline ThuilletMarion VideauPublished in: IACR Cryptol. ePrint Arch. (2009)