Partial Sums Meet FFT: Improved Attack on 6-Round AES
Orr Dunkelman, Shibam Ghosh, Nathan Keller, Gaëtan Leurent, Avichai Marmor, Victor Mollimard
Abstract
. The partial sums cryptanalytic technique was introduced in 2000 by Ferguson et al., who used it to break 6-round AES with time complexity of 2 52 S-box computations – a record that has not been beaten ever since. In 2014, Todo and Aoki showed that for 6-round AES, partial sums can be replaced by a technique based on the Fast Fourier Transform (FFT), leading to an attack with a comparable complexity. In this paper we show that the partial sums technique can be combined with an FFT-based technique, to get the best of the two worlds. Using our combined technique, we obtain an attack on 6-round AES with complexity of about 2 46 . 4 additions. We fully implemented the attack experimentally, along with the partial sums attack and the Todo-Aoki attack, and confirmed that our attack improves the best known attack on 6-round AES by a factor of more than 32. We expect that our technique can be used to significantly enhance numerous attacks that exploit the partial sums technique. To demonstrate this, we use our technique to improve the best known attack on 7-round Kuznyechik by a factor of more than 80, and to reduce the complexity of the best known attack on the full MISTY1 from 2 69 . 5 to 2 67 .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- Improved Differential-Linear Attacks with Applications to ARX CiphersChristof Beierle, Gregor Leander, Yosuke TodoCRYPTO 2020 · 57 citations
- The Retracing Boomerang AttackOrr Dunkelman, Nathan Keller, Eyal Ronen, Adi ShamirEUROCRYPT 2020 · 53 citations
- Truncated Boomerang Attacks and Application to AES-Based CiphersAugustin Bariant, Gaëtan LeurentEUROCRYPT 2023 · 29 citations
- TNT: How to Tweak a Block CipherZhenzhen Bao, Chun Guo, Jian Guo, Ling SongEUROCRYPT 2020 · 20 citations
Related papers
- Exploiting Non-full Key Additions: Full-Fledged Automatic Demirci-Selçuk Meet-in-the-Middle Cryptanalysis of SKINNYDanping Shi, Siwei Sun, Ling Song, Lei Hu et al.EUROCRYPT 2023 · 9 citations
- Triangulating Meet-in-the-Middle AttackBoxin Zhao, Qingliang Hou, Lingyue Qin, Xiaoyang DongCRYPTO 2025 · 1 citation
- Improving Key-Recovery in Linear Attacks: Application to 28-Round PRESENTAntonio Flórez-Gutiérrez, María Naya-PlasenciaEUROCRYPT 2020 · 39 citations
- Differential Meet-In-The-Middle CryptanalysisChristina Boura, Nicolas David, Patrick Derbez, Gregor Leander et al.CRYPTO 2023 · 24 citations
- Secure Wire Shuffling in the Probing ModelJean-Sébastien Coron, Lorenzo SpignoliCRYPTO 2021 · 13 citations
