Lune

CRYPTO2026Top-tier venue

Meet-in-the-Middle Attacks on Full ChiLow

Eran Lambooij, Patrick Neumann, Michiel Verbauwhede, Shichang Wang, Tianyu Zhang

2026Year

Abstract

This work presents the first full-round attacks on ChiLow-32 and ChiLow-40, two tweakable low-latency block ciphers presented at Eurocrypt 2025.

We first describe a straightforward Meet-in-the-Middle attack on full ChiLow-32 with multiple known plaintext-ciphertext pairs. To improve this attack, we carefully reduce the number of guesses required by (1) tracing differences in order to remove linear key dependencies and (2) moving from key guesses to state guesses. Using a novel method that is based on the propagation of differences and linear masks, we are able to map out the state dependencies for computing the difference at the matching point. This results in an attack on ChiLow-32 with time complexity 2120.342^{120.34} using 160160 known plaintext-ciphertext pairs, and an attack with time complexity 2102.092^{102.09} using 6464 chosen ciphertexts.

Using these techniques, and an additional trick to better balance the complexities of the meet-in-the-middle branches, we propose an attack on ChiLow-40 with time complexity 2122.322^{122.32} and 282^8 chosen plaintexts. All of our attacks are within ChiLow's security model, and are currently the best and only known key recovery attacks on full-round ChiLow-32 and ChiLow-40.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 8560c2d2-1bec-49d6-b463-77ee9aa364ce

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines