Lune

CRYPTO2023Top-tier venue

On Perfect Linear Approximations and Differentials over Two-Round SPNs

Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann, Lukas Stennes

2023Year
5Citations

Abstract

Recent constructions of (tweakable) block ciphers with an embedded cryptographic backdoor relied on the existence of probability-one differentials or perfect (non-)linear approximations over a reduced-round version of the primitive. In this work, we study how the existence of probability-one differentials or perfect linear approximations over two rounds of a substitution-permutation network can be avoided by design. More precisely, we develop criteria on the s-box and the linear layer that guarantee the absence of probability-one differentials for all keys. We further present an algorithm that allows to efficiently exclude the existence of keys for which there exists a perfect linear approximation.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 9ca7e5db-e5c9-4b6a-acf7-aa18f15668b7

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines