Rotational Cryptanalysis from a Differential-Linear Perspective - Practical Distinguishers for Round-Reduced FRIET, Xoodoo, and Alzette
Yunwen Liu, Siwei Sun, Chao Li
Abstract
The differential-linear attack, combining the power of the two most effective techniques for symmetric-key cryptanalysis, was proposed by Langford and Hellman at CRYPTO 1994. From the exact formula for evaluating the bias of a differential-linear distinguisher (JoC 2017), to the differential-linear connectivity table (DLCT) technique for dealing with the dependencies in the switch between the differential and linear parts (EUROCRYPT 2019), and to the improvements in the context of cryptanalysis of ARX primitives (CRYPTO 2020), we have seen significant development of the differential-linear attack during the last four years. In this work, we further extend this framework by replacing the differential part of the attack by rotational-xor differentials. Along the way, we establish the theoretical link between the rotational-xor differential and linear approximations, revealing that it is nontrivial to directly apply the closed formula for the bias of ordinary differential- linear attack to rotational differential-linear cryptanalysis. We then revisit the rotational cryptanalysis from the perspective of differential- linear cryptanalysis and generalize Morawiecki et al.’s technique for analyzing Keccak, which leads to a practical method for estimating the bias of a (rotational) differential-linear distinguisher in the special case where the output linear mask is a unit vector. Finally, we apply the rotational differential-linear technique to the permutations involved in FRIET, Xoodoo, Alzette, and SipHash. This gives significant improvements over existing cryptanalytic results or offers explanations for previous experimental distinguishers without a theoretical foundation. To confirm the validity of our analysis, all distinguishers with practical complexities are verified experimentally.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 95e281d7-3018-4e90-a1d1-0879c5ebd218Cited by top-tier papers2
- Rotational Differential-Linear Distinguishers of ARX Ciphers with Arbitrary Output Linear MasksZhongfeng Niu, Siwei Sun, Yunwen Liu, Chao LiCRYPTO 2022 · 29 citations
- Revisiting Differential-Linear Attacks via a Boomerang Perspective with Application to AES, Ascon, CLEFIA, SKINNY, PRESENT, KNOT, TWINE, WARP, LBlock, Simeck, and SERPENTHosein Hadipour, Patrick Derbez, Maria EichlsederCRYPTO 2024 · 21 citations
Related papers
- Improved Differential-Linear Attacks with Applications to ARX CiphersChristof Beierle, Gregor Leander, Yosuke TodoCRYPTO 2020 · 57 citations
- Differential-Linear Cryptanalysis from an Algebraic PerspectiveMeicheng Liu, Xiaojuan Lu, Dongdai LinCRYPTO 2021 · 47 citations
- Preimage Attacks on up to 5 Rounds of SHA-3 Using Internal DifferentialsZhongyi Zhang, Chengan Hou, Meicheng LiuEUROCRYPT 2025 · 1 citation
- A Generic Algorithm for Efficient Key Recovery in Differential Attacks - and its Associated ToolChristina Boura, Nicolas David, Patrick Derbez, Rachelle Heim Boissier et al.EUROCRYPT 2024 · 11 citations
- Differential Meet-In-The-Middle CryptanalysisChristina Boura, Nicolas David, Patrick Derbez, Gregor Leander et al.CRYPTO 2023 · 24 citations
