Addendum to Linear Cryptanalyses of Three AEADs with GIFT-128 as Underlying Primitives

IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY(2022)

引用 0|浏览4
暂无评分
摘要
In ToSC 2021(2), Sun et al. implemented an automatic search with the Boolean satisfiability problem (SAT) method on GIFT-128 and identified a 19-round linear approximation with the expected linear potential being 2(-117.43), which is utilised to launch a 24-round attack on the cipher. In this addendum, we discover a new 19-round linear approximation with a lower expected linear potential. However, in the attack, one more round can be appended after the distinguisher. As a result, we improve the previous optimal linear attack by one round and put forward a 25-round linear attack. Given that the optimal differential attack on GIFT-128, for now, covers 27-round, the resistances of the cipher against differential and linear attacks still have a 2-round gap.
更多
查看译文
关键词
Differential cryptanalysis, Linear cryptanalysis, GIFT-128
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要