Cryptanalytic Properties of Mealy Machines
Zhongfeng Niu, Tim Beyne, Kai Hu, Meiqin Wang
Abstract
This paper proposes a systematic approach to compute cryptanalytic properties of arbitrary Mealy machines or S-functions. Based on the geometric approach to cryptanalysis, we provide a uniform formula for any cryptanalytic property of such a function, as long as the property is compatible with the way its input and output are split into chunks. Examples include linear, (quasi) differential, (ultrametric) integral, differential-linear, and boomerang properties. To illustrate our results, we compute these properties for several important examples, including modular additions, the Chi- and ChiChi-functions, and the SHA-1 step function. As proof-of-concept applications, we construct a boomerang distinguisher for the Subterranean permutation, and show how to compute the correlations of conditional linear approximations in partitioning-based differential-linear attacks more accurately. Our results also lead to a new approach to compute the algebraic normal form of the inverse of the Chi-function.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8aa6be41-f57e-413b-8fe2-c8f9cbc2901fRelated papers
- Efficient Detection of High Probability Statistical Properties of Cryptosystems via Surrogate DifferentiationItai Dinur, Orr Dunkelman, Nathan Keller, Eyal Ronen et al.EUROCRYPT 2023 · 5 citations
- Rotational Cryptanalysis from a Differential-Linear Perspective - Practical Distinguishers for Round-Reduced FRIET, Xoodoo, and AlzetteYunwen Liu, Siwei Sun, Chao LiEUROCRYPT 2021 · 24 citations
- Algorithmic Toolkit for Linearization of S-BoxesAlex Biryukov, Philip Turecek, Aleksei UdovenkoEUROCRYPT 2026
- When the Wrong Key Lives On: The Key-Recovery Procedure in Integral AttacksChristof Beierle, Gregor Leander, Yevhen PerehudaEUROCRYPT 2026
- Probabilistic Linearization: Internal Differential Collisions in up to 6 Rounds of SHA-3Zhongyi Zhang, Chengan Hou, Meicheng LiuCRYPTO 2024 · 7 citations
