Meet-in-the-Middle Attacks on Full ChiLow
Eran Lambooij, Patrick Neumann, Michiel Verbauwhede, Shichang Wang, Tianyu Zhang
Abstract
This work presents the first full-round attacks on ChiLow-32 and ChiLow-40, two tweakable low-latency block ciphers presented at Eurocrypt 2025.
We first describe a straightforward Meet-in-the-Middle attack on full ChiLow-32 with multiple known plaintext-ciphertext pairs. To improve this attack, we carefully reduce the number of guesses required by (1) tracing differences in order to remove linear key dependencies and (2) moving from key guesses to state guesses. Using a novel method that is based on the propagation of differences and linear masks, we are able to map out the state dependencies for computing the difference at the matching point. This results in an attack on ChiLow-32 with time complexity using known plaintext-ciphertext pairs, and an attack with time complexity using chosen ciphertexts.
Using these techniques, and an additional trick to better balance the complexities of the meet-in-the-middle branches, we propose an attack on ChiLow-40 with time complexity and chosen plaintexts. All of our attacks are within ChiLow's security model, and are currently the best and only known key recovery attacks on full-round ChiLow-32 and ChiLow-40.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8560c2d2-1bec-49d6-b463-77ee9aa364ceRelated papers
- ChiLow and ChiChi: New Constructions for Code EncryptionYanis Belkheyar, Patrick Derbez, Shibam Ghosh, Gregor Leander et al.EUROCRYPT 2025 · 7 citations
- Improved Differential Meet-in-the-Middle CryptanalysisZahra Ahmadian, Akram Khalesi, Dounia M'foukh, Hossein Moghimi et al.EUROCRYPT 2024 · 14 citations
- Cryptanalysis of Full SCARFAntonio Flórez-Gutiérrez, Eran Lambooij, Gaëtan Leurent, Håvard Raddum et al.EUROCRYPT 2025 · 2 citations
- Differential Meet-In-The-Middle CryptanalysisChristina Boura, Nicolas David, Patrick Derbez, Gregor Leander et al.CRYPTO 2023 · 24 citations
- Exploiting Strong Key Bridges: Full-Fledged Automatic Rectangle Attacks on Deoxys-BC and SKINNYLing Song, Yincen Chen, Qianqian Yang, Huimin Liu et al.CRYPTO 2026
