Algorithmic Toolkit for Linearization of S-Boxes
Alex Biryukov, Philip Turecek, Aleksei Udovenko
摘要
Linearization is a cryptanalysis technique in which a nonlinear function (an S-box) is represented by an affine mapping on a certain subset of inputs. Its variants were applied to analyze Keccak, LowMC, RAIN and AIM. In these primitives, the S-boxes are either very small (up to 5 bits) or are very specific monomial functions over a binary field. Linearization of arbitrary S-boxes was never practically explored due to the lack of theoretic, algorithmic, and cryptanalytic understanding.
For the first time, we develop an algorithmic toolkit which allows one to compute strong linearizations of S-boxes, when they exist. For up to bits, our algorithms are able to find provably the best possible approximations, while for larger S-boxes it is feasible to obtain good approximations together with meaningful upper bounds. We apply our algorithms to a variety of S-boxes from existing primitives, to monomial functions, to so-called APN functions, and to 16-bit Super-Sboxes. We obtain interesting results raising many new open questions and open up new research directions, as well as a foundation for developing cryptanalytic attacks.
To advance the cryptanalytic utility of linearization, we study and solve the problem of covering an S-box with multiple approximations. As an application, we derive a generic linearization approach for the CICO problem (constrained-input-constrained-output) over SPN-based permutations (Substitution-Permutation Networks) with general linear layers. This is the first such general cryptanalysis based on the existence of a strong linearization of the S-box.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Coefficient Grouping for Complex Affine LayersFukang Liu, Lorenzo Grassi, Clémence Bouvier, Willi Meier 等CRYPTO 2023 · 被引用 10 次
- Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl 等CRYPTO 2020 · 被引用 2 次
- Efficient Detection of High Probability Statistical Properties of Cryptosystems via Surrogate DifferentiationItai Dinur, Orr Dunkelman, Nathan Keller, Eyal Ronen 等EUROCRYPT 2023 · 被引用 5 次
- Cryptanalytic Properties of Mealy MachinesZhongfeng Niu, Tim Beyne, Kai Hu, Meiqin WangCRYPTO 2026
- A Generic Algorithm for Efficient Key Recovery in Differential Attacks - and its Associated ToolChristina Boura, Nicolas David, Patrick Derbez, Rachelle Heim Boissier 等EUROCRYPT 2024 · 被引用 11 次
