CryptoDB
Addendum to Linear Cryptanalyses of Three AEADs with GIFT-128 as Underlying Primitives
| Authors: |
|
|---|---|
| Download: | |
| Abstract: | In ToSC 2021(2), Sun et al. implemented an automatic search with the Boolean satisfiability problem (SAT) method on GIFT-128 and identified a 19-round linear approximation with the expected linear potential being 2−117.43, which is utilised to launch a 24-round attack on the cipher. In this addendum, we discover a new 19-round linear approximation with a lower expected linear potential. However, in the attack, one more round can be appended after the distinguisher. As a result, we improve the previous optimal linear attack by one round and put forward a 25-round linear attack. Given that the optimal differential attack on GIFT-128, for now, covers 27-round, the resistances of the cipher against differential and linear attacks still have a 2-round gap. |
BibTeX
@article{tosc-2022-31979,
title={Addendum to Linear Cryptanalyses of Three AEADs with GIFT-128 as Underlying Primitives},
journal={IACR Transactions on Symmetric Cryptology},
publisher={Ruhr-Universität Bochum},
volume={2022, Issue 1},
pages={212-219},
url={https://tosc.iacr.org/index.php/ToSC/article/view/9534},
doi={10.46586/tosc.v2022.i1.212-219},
author={Ling Sun and Wei Wang and Meiqin Wang},
year=2022
}