Key Guessing Strategies for Linear Key-Schedule Algorithms in Rectangle Attacks
Xiaoyang Dong, Lingyue Qin, Siwei Sun, Xiaoyun Wang
Abstract
When generating quartets for the rectangle attacks on ciphers with linear key-schedule, we find the right quartets which may suggest key candidates have to satisfy some nonlinear relations. However, some quartets generated always violate these relations, so that they will never suggest any key candidates. Inspired by previous rectangle frameworks, we find that guessing certain key cells before generating quartets may reduce the number of invalid quartets. However, guessing a lot of key cells at once may lose the benefit from the early abort technique, which may lead to a higher overall complexity. To get better tradeoff, we build a new rectangle framework on ciphers with linear key-schedule with the purpose of reducing overall complexity or attacking more rounds. In the tradeoff model, there are many parameters affecting the overall complexity, especially for the choices of the number and positions of key guessing cells before generating quartets. To identify optimal parameters, we build a uniform automatic tool on SKINNY as an example, which includes the optimal rectangle distinguishers for key-recovery phase, the number and positions of guessing key cells before generating quartets, the size of key counters to build that affecting the exhaustive search step, etc. Based on the automatic tool, we identify a 32-round key-recovery attack on SKINNY-128-384 in the related-key setting, which extends the best previous attack by 2 rounds. For other versions with n-2n or n-3n, we also achieve one more round than before. In addition, using the previous rectangle distinguishers, we achieve better attacks on round-reduced ForkSkinny, Deoxys-BC-384 and GIFT-64. At last, we discuss the conversion of our rectangle framework from related-key setting into single-key setting and give new single-key rectangle attack on 10-round Serpent.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2f7949ed-c5b6-457e-b5f2-6228d5a0e0ffCited by top-tier papers3
- Revisiting Differential-Linear Attacks via a Boomerang Perspective with Application to AES, Ascon, CLEFIA, SKINNY, PRESENT, KNOT, TWINE, WARP, LBlock, Simeck, and SERPENTHosein Hadipour, Patrick Derbez, Maria EichlsederCRYPTO 2024 · 21 citations
- A Generic Algorithm for Efficient Key Recovery in Differential Attacks - and its Associated ToolChristina Boura, Nicolas David, Patrick Derbez, Rachelle Heim Boissier et al.EUROCRYPT 2024 · 11 citations
- A Greater GIFT: Strengthening GIFT Against Statistical CryptanalysisLing Sun, Bart Preneel, Wei Wang, Meiqin WangEUROCRYPT 2022 · 6 citations
Related papers
- Probabilistic Extensions: A One-Step Framework for Finding Rectangle Attacks and BeyondLing Song, Qianqian Yang, Yincen Chen, Lei Hu et al.EUROCRYPT 2024 · 10 citations
- Exploiting Strong Key Bridges: Full-Fledged Automatic Rectangle Attacks on Deoxys-BC and SKINNYLing Song, Yincen Chen, Qianqian Yang, Huimin Liu et al.CRYPTO 2026
- Differential Meet-In-The-Middle CryptanalysisChristina Boura, Nicolas David, Patrick Derbez, Gregor Leander et al.CRYPTO 2023 · 24 citations
- Exploiting Non-full Key Additions: Full-Fledged Automatic Demirci-Selçuk Meet-in-the-Middle Cryptanalysis of SKINNYDanping Shi, Siwei Sun, Ling Song, Lei Hu et al.EUROCRYPT 2023 · 9 citations
- Improved Differential Meet-in-the-Middle CryptanalysisZahra Ahmadian, Akram Khalesi, Dounia M'foukh, Hossein Moghimi et al.EUROCRYPT 2024 · 14 citations
