International Association for Cryptologic Research

International Association
for Cryptologic Research


Improving Key Recovery Linear Attacks with Walsh Spectrum Puncturing

Antonio Flórez-Gutiérrez , NTT Social Informatics Laboratories
Yosuke Todo , NTT Social Informatics Laboratories
DOI: 10.1007/978-3-031-58716-0_7 (login may be required)
Search ePrint
Search Google
Presentation: Slides
Conference: EUROCRYPT 2024
Abstract: In some linear key recovery attacks, the function which determines the value of the linear approximation is replaced by a similar map in order to improve the time or memory complexity at the cost of a data complexity increase. We propose a general framework for key recovery map substitution, and introduce Walsh spectrum puncturing, which consists of removing carefully-chosen coefficients from the Walsh spectrum of this map. The capabilities of this technique are illustrated by describing improved attacks on reduced-round Serpent (including the first 12-round attack on the 192-bit key variant), GIFT-128 and NOEKEON, as well as the full DES.
  title={Improving Key Recovery Linear Attacks with Walsh Spectrum Puncturing},
  author={Antonio Flórez-Gutiérrez and Yosuke Todo},