Massive Superpoly Recovery with a Meet-in-the-Middle Framework - Improved Cube Attacks on Trivium and Kreyvium
Jiahui He, Kai Hu, Hao Lei, Meiqin Wang
摘要
The cube attack extracts the information of secret key bits by recovering the coefficient called superpoly in the output bit with respect to a subset of plaintexts/IV, which is called a cube. While the division property provides an efficient way to detect the structure of the superpoly, superpoly recovery could still be prohibitively costly if the number of rounds is sufficiently high. In particular, Core Monomial Prediction (CMP) was proposed at ASIACRYPT 2022 as a scaled-down version of Monomial Prediction (MP), which sacrifices accuracy for efficiency but ultimately gets stuck at 848 rounds of .
In this paper, we provide new insights into CMP by elucidating the algebraic meaning to the core monomial trails. We prove that it is sufficient to recover the superpoly by extracting all the core monomial trails, an approach based solely on CMP, thus demonstrating that CMP can achieve perfect accuracy as MP does. We further reveal that CMP is still MP in essence, but with variable substitutions on the target function. Inspired by the divide-and-conquer strategy that has been widely used in previous literature, we design a meet-in-the-middle (MITM) framework, in which the CMP-based approach can be embedded to achieve a speedup.
To illustrate the power of these new techniques, we apply the MITM framework to , and . As a result, not only can the previous computational cost of superpoly recovery be reduced (e.g., 5x faster for superpoly recovery on 192-round ), but we also succeed in recovering superpolies for up to 851 rounds of and up to 899 rounds of . This surpasses the previous best results by respectively 3 and 4 rounds. Using the memory-efficient Möbius transform proposed at EUROCRYPT 2021, we can perform key recovery attacks on target ciphers, even though the superpoly may contain over monomials. This leads to the best cube attacks on the target ciphers.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks Against Trivium and Grain-128AEADYonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo 等EUROCRYPT 2020 · 被引用 64 次
- Triangulating Meet-in-the-Middle AttackBoxin Zhao, Qingliang Hou, Lingyue Qin, Xiaoyang DongCRYPTO 2025 · 被引用 1 次
- Improved Differential Meet-in-the-Middle CryptanalysisZahra Ahmadian, Akram Khalesi, Dounia M'foukh, Hossein Moghimi 等EUROCRYPT 2024 · 被引用 14 次
- Triangulating Rebound Attack on AES-like HashingXiaoyang Dong, Jian Guo, Shun Li, Phuong PhamCRYPTO 2022 · 被引用 19 次
- Differential Meet-In-The-Middle CryptanalysisChristina Boura, Nicolas David, Patrick Derbez, Gregor Leander 等CRYPTO 2023 · 被引用 24 次
