On Perfect Linear Approximations and Differentials over Two-Round SPNs
Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann, Lukas Stennes
Abstract
Recent constructions of (tweakable) block ciphers with an embedded cryptographic backdoor relied on the existence of probability-one differentials or perfect (non-)linear approximations over a reduced-round version of the primitive. In this work, we study how the existence of probability-one differentials or perfect linear approximations over two rounds of a substitution-permutation network can be avoided by design. More precisely, we develop criteria on the s-box and the linear layer that guarantee the absence of probability-one differentials for all keys. We further present an algorithm that allows to efficiently exclude the existence of keys for which there exists a perfect linear approximation.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9ca7e5db-e5c9-4b6a-acf7-aa18f15668b7Related papers
- The MALICIOUS Framework: Embedding Backdoors into Tweakable Block CiphersThomas Peyrin, Haoyang WangCRYPTO 2020 · 23 citations
- The t-wise Independence of Substitution-Permutation NetworksTianren Liu, Stefano Tessaro, Vinod VaikuntanathanCRYPTO 2021 · 17 citations
- Thinking Outside the SuperboxNicolas Bordes, Joan Daemen, Daniël Kuijsters, Gilles Van AsscheCRYPTO 2021 · 15 citations
- New Techniques for Analyzing Differentials with Application to AESItai DinurEUROCRYPT 2026
- Efficient Detection of High Probability Statistical Properties of Cryptosystems via Surrogate DifferentiationItai Dinur, Orr Dunkelman, Nathan Keller, Eyal Ronen et al.EUROCRYPT 2023 · 5 citations
