2026-03-16
Cheng Che, Tian Tian
ChiLow is a family of tweakable block ciphers specifically designed for embedded code encryption, proposed at EUROCRYPT 2025. Its novel nested tweakkey schedule and a variant of the χ function significantly enhance latency and energy efficiency. This paper presents a security analysis of ChiLow from the perspectives of differential-linear cryptanalysis and cube attacks, filling some gaps in the initial security analysis made by the designers. Our main contributions are threefold: (1) Distinguishing attacks based on differential-linear cryptanalysis that can distinguish full-round ChiLow from random permutations. For ChiLow-(32+ τ ), both the time complexity and data complexity of the attack are 2 81.03 ; for ChiLow-40, both complexities are 2 88.91 . We note that the data complexities of these distinguishing attacks are valid since an adversary could query multiple devices. (2) Key recovery attacks on full-round ChiLow based on differential-linear cryptanalysis with the time complexity better than the exhaustive key search. These attacks achieve a time complexity of 2 121 , with data complexities of 2 79.5 for ChiLow-(32+ τ ) and 2 88.42 for ChiLow-40 exceeding the data limit for one key. (3) A key recovery attack on 6-round ChiLow based on cube attacks, with a time complexity of 2 68 and a data complexity of 2 33 respecting the limit of the total number of queries. These results shed some new light on the security boundaries of ChiLow and provide valuable insights for designing low-latency ciphers in embedded systems.
2026-03-16
Yuchao Chen, Chun Guo, Muzhou Li, Shuo Peng, Hao Lei, Guang Zeng, Meiqin Wang
(Multi-branch) Generalized Feistel Network (GFN) enables the construction of block ciphers from non-linear components with small domains, and has been adopted in various block ciphers. Berger et al. (SAC 2013) introduced the Extended Generalized Feistel Network (EGFN), which unified and extended existing Feistel-like structures by using a matrix representation. Given an arbitrary matrix, it is typically difficult to determine how many EGFN rounds are sufficient for pseudorandom permutation (PRP) and strong PRP (SPRP) security. Remarkably, security proofs for structures with a larger number of branches have to analyze a huge amount of collision events, which is overly complicated and prone to errors. To remedy this situation, we present AutoEGFN, a computer-aided proof tool that determines the number of rounds sufficient for PRP and SPRP security for various variants of EGFN. The tool operates by calculating three parameters: r 1 , r 2 , and r 3 . The validity and soundness of AutoEGFN are formally established by a detailed security proof. To demonstrate the effectiveness of AutoEGFN, we have applied it to multiple structures such as Type-1/2 GFN (Zheng et al., CRYPTO 1989), YI11’s Type-1 GFN (Yanagihara and Iwata, CANS 2011), DFLM19’s GFN (Derbez et al., FSE 2019), DDGP22’s GFN (Delaune et al., INDOCRYPT 2022), Type-1.x GFN (Yanagihara and Iwata, IEICE 2014), SH/TH GFN (Yanagihara and Iwata, CANS 2011), Nyberg’s GFN (Nyberg, ASIACRYPT 1996), SM’s GFN (Suzaki and Minematsu, FSE 2010), and BMT’s EGFN (Berger et al., SAC 2013). As a result, we provide a systematic analysis of the (S)PRP security for Type-1 and Type-2 structures for different numbers of branches. Our tool efficiently determines the concrete number of rounds required to ensure PRP and SPRP security for EGFNs with different branch numbers. For comparison, previous work only proved the (S)PRP security for 8- and 16-branch BMT’s EGFN. Our tool completes the proof within several minutes, even for variants with 32 branches. Meanwhile, for the other structures, we provide the first concrete (S)PRP security proofs without any restrictions on their permutation layers. Furthermore, AutoEGFN will significantly contribute to the enhancement of EGFN designs and implementations in various cryptographic applications.
2026-03-16
Jianhua Wang, Tao Huang, Siwei Sun, Hailun Yan, Guang Zeng, Shuang Wu
This paper introduces a new cryptographic notion for diffusion matrices, termed the Differential Pattern Transition (DPT). Building on this notion, we develop a systematic framework for describing the differential behavior of diffusion layers over multiple rounds in AES-like block ciphers. Specifically, the DPT framework enables a finer-grained evaluation of diffusion strength against differential attacks, allowing distinctions even among matrices sharing the same branch number. Furthermore, the DPT framework facilitates the classification of shuffle layers and assists in identifying permutation layers that maximize differential resistance. As a case study, we apply the DPT framework to the diffusion matrices used in MIDORI, PRINCE, QARMA, and AES, as well as a lightweight MDS matrix proposed in [SS16]. The results show that DPT provides both theoretical insights and practical guidance for the selection and design of diffusion and shuffle layers in secure and efficient block cipher constructions.
2026-03-16
Shiyao Chen, Jian Guo, Tianyu Zhang
This work presents the first third-party cryptanalysis of Blink, a recent tweakable block cipher built on the Three-Hash Framework with a long-key design. Leveraging the idea of Superbox, we develop a lightweight theoretical model capturing the value correlations, weak-key conditions, fixed-key probabilities and the local clustering behaviors inside a Blink Superbox when the value spaces are affine. This model is intended as a concrete, easy-to-follow specialization of existing generic frameworks adapted to the structure of Blink. We then build a simple pattern-based automatic tool to search for weak tweak-key differentials. The main results are as follows: For Blink-64 with 448-bit key size, we obtain a 10-round distinguisher with probability 2 −50.42 for up to 2 442 weak keys (equivalently 2 −6 of the full key space); For Blink-128 with 1024-bit key size, we obtain a 10-round distinguisher with probability 2 −68.83 for up to 2 1010 weak keys (equivalently 2 −14 of the full key space), which can be extended to a 12-round multiple differential distinguisher with probability 2 −96.83 . Based on the weak tweak-key distinguisher, we further mount a 13-round key recovery attack on Blink-64, recovering the full 448-bit master key with time complexity 2 114.02 and 2 56 chosen plaintexts. All these distinguishers and key recovery attacks work within the data and time bounds claimed by the designers. And our analysis remains consistent with the security of the full-round design of Blink, while offering additional insight into the edge-case behaviors arising from the tweak-key interaction in Blink, and could be potentially informative for future refinements of tweakable block cipher constructions.
2026-03-16
Hongli Li, Changlun Li, Honggang Hu, Fengmei Liu
The sponge construction is subject to an indifferentiability security bound of c /2 bits, where c denotes the capacity. For a given b -bit permutation, the sponge construction allows sacrificing the rate r = b − c to achieve the theoretically optimal security bound of ( b −1)/2 bits. However, the efficient construction of a permutationbased hash with b /2-bit security remains an open problem. In this paper, we analyze the porifera family, a class of generalized sponge functions including existing designs such as JH and FP. We introduce the t -way chosen multitarget ( t -CMT) preimage resistance and propose the Universal San Mai Attack (USMA) to target this property. We reduce the indifferentiability bound for both JH and FP to b /3 bits, which is lower than previously assumed. Furthermore, we classify the porifera family and prove that, under a restriction on the linear layer complexity, there exists a unique design, named VFB, that achieves the optimal security bound of approximately b /2 bits. Although it requires r ≥ c and a distinct finalization, it provides higher throughput for high-security parameters. For instance, using a 1600-bit permutation, VFB achieves 512-bit security at a rate of 1064 bits, exceeding the rate of Keccak-512.
2026-03-16
Chengan Hou, Shuyi Wang, Meicheng Liu
Linear cryptanalysis has long served as a cornerstone in the security analysis of symmetric-key cryptanalytic primitives. Through more than 30 years of community efforts, it has become routine to use automated tools to search for the optimal linear approximations. In stark contrast, the key recovery part is still far from automation and optimization. The situation became even more challenging after the work of Flórez-Gutiérrez and Todo [FT24], where the newly introduced Walsh Spectrum Puncturing (WSP) technique brought a large number of candidate key recovery map approximations. In this paper, we formally prove that the approximate key recovery map proposed by [FT24] is the optimal strategy for Bit Puncturing and LAT Subspace Puncturing. We then propose an MILP model to automatically search for the optimal approximate key recovery map for WSP. The automated model is used to improve the linear key recovery attack on the AES finalist Serpent and the ISO standard PRESENT. We reduce the time complexity of the 12-round Serpent key recovery attack to 2 184.8 (from 2 189.7 ) for Serpent-192 and to 2 200.4 (from 2 210.4 ) for Serpent-256. For PRESENT-128, we update the key recovery attack on its 29-round variant, and extend the attack to 30 rounds for the first time.
2025-12-17
Thomas Peters, Sayandeep Saha, Yaobin Shen, François-Xavier Standaert
Physical attacks are one of the potent threats to modern cryptography. Symmetric-key primitives are well-explored with respect to passive, active, and more recently combined (i.e., simultaneously leaking and faulting) adversaries. For symmetric key operating modes, there are many proposals for encryption (ENC), Message Authentication Codes (MAC), and Authenticated Encryption (AE) covering passive attacks. However, research on active or combined adversaries is more succinct and, to the best of our knowledge, boils down to combined secure MAC due to Berti et al. (ToSC 2023, issue 1), combined secure ENC due to Dobraunig et al. (CCS’22), and active secure AE named MEM due to Saha et al. (ToSC 2022, issue 4). Our first contribution is a security model to formally reason about the combined security of AE. The model extends the fault-then-leak security of MAC introduced by Berti et al. to AE and can also be seen as a natural extension of state-of-the-art leakage resistant notions in their so-called faulty matrix framework. Armed with this model, we show as a second contribution that all the leakage-resilient, including leakage-resistant, AE constructions and the fault-resilient MEM construction are vulnerable to a single fault injection within the composition of their building blocks. These decoupling attacks remain successful even for combined-secure building blocks. As a result, we finally present LEAF, the first AE construction secure against faultthen- leak adversaries with a single fault injection. In encryption, LEAF makes only one call to a MAC and two calls to an ENC that are combined secure.
2025-12-17
Subhadeep Banik, Tatsuya Ishikawa, Takanori Isobe, Ryoma Ito, Kazuhiko Minematsu, Kazuma Nakata, Mostafizar Rahman, Kosei Sakamoto
In this paper, we propose Dialga, a family of low-latency tweakable block ciphers designed to support 128/256-bit tweaks and 256-bit keys. Dialga achieves significantly small latency by leveraging multiple novel strategies. These include the use of multiple linear layers with efficient cell permutations, which enhance security against differential and linear attacks with negligible hardware overhead. We also identify the optimal choice of S-boxes for these permutations using state-ofthe- art evaluation methods by SAT, enabling us to further reduce the delay of the round function. Besides, we design a reflection tweakey schedule that ensures strong security in the related-tweak setting and allows for encryption and decryption without delay overhead, reducing the circuit area. We conducted comprehensive hardware benchmarks involving Dialga and other primitives. As a result, Dialga achieves nearly half the delay of QARMAv2, while achieving approximately a 40% reduction in area, with the same claimed security.